XPath Injection Vulnerability in Novell ZENworks Configuration Management
CVE-2015-5970
5.3MEDIUM
Key Information:
- Vendor
- Novell
- Vendor
- CVE Published:
- 18 February 2016
Summary
The ChangePassword RPC method found in Novell ZENworks Configuration Management versions 11.3 and 11.4 is susceptible to XPath injection attacks. Exploiting this vulnerability allows remote attackers to craft a malicious query that manipulates a system entity reference, enabling unauthorized access to read arbitrary text files within the system.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved