XPath Injection Vulnerability in Novell ZENworks Configuration Management
CVE-2015-5970

5.3MEDIUM

Key Information:

Vendor
Novell
Vendor
CVE Published:
18 February 2016

Summary

The ChangePassword RPC method found in Novell ZENworks Configuration Management versions 11.3 and 11.4 is susceptible to XPath injection attacks. Exploiting this vulnerability allows remote attackers to craft a malicious query that manipulates a system entity reference, enabling unauthorized access to read arbitrary text files within the system.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.