Novell / Zenworks Configuration Management
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-6345 | Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. | HIGH | 7.5 | Jan 25, 2020 |
| CVE-2012-6344 | Novell ZENworks Configuration Management before 11.2.4 allows XSS. | MEDIUM | 6.1 | Jan 25, 2020 |
| CVE-2015-0786 | Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attacker… | CRITICAL | 9.8 | Aug 9, 2017 |
| CVE-2015-0785 | com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders v… | HIGH | 7.5 | Aug 9, 2017 |
| CVE-2015-0784 | Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for t… | HIGH | 7.5 | Aug 9, 2017 |
| CVE-2015-0783 | The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable. | MEDIUM | 6.5 | Aug 9, 2017 |
| CVE-2015-0782 | SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to exec… | CRITICAL | 9.8 | Aug 9, 2017 |
| CVE-2015-0781 | Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload… | CRITICAL | 9.8 | Aug 9, 2017 |
| CVE-2015-0780 | SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attacke… | CRITICAL | 9.8 | Aug 9, 2017 |
| CVE-2015-5970 | The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and r… | MEDIUM | 5.3 | Feb 18, 2016 |
| CVE-2015-0779 | Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute… | HIGH | 10.0 | Jun 7, 2015 |
| CVE-2010-5324 | Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows r… | HIGH | 10.0 | Jun 7, 2015 |
| CVE-2010-5323 | Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows r… | HIGH | 10.0 | Jun 7, 2015 |
| CVE-2014-7169 KEV | bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) | CRITICAL | 9.8 | Sep 25, 2014 |
| CVE-2014-6271 KEV | bash: specially-crafted environment variables can be used to inject shell commands | CRITICAL | 9.8 | Sep 24, 2014 |
| CVE-2013-3706 | Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files… | MEDIUM | 5.0 | Mar 6, 2014 |
| CVE-2013-6347 | Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified v… | MEDIUM | 6.8 | Nov 2, 2013 |
| CVE-2013-6346 | Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hija… | MEDIUM | 6.8 | Nov 2, 2013 |
| CVE-2013-6345 | Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "… | HIGH | 10.0 | Nov 2, 2013 |
| CVE-2013-6344 | The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors. | MEDIUM | 4.3 | Nov 2, 2013 |
| CVE-2013-1084 | Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers… | MEDIUM | 5.0 | Nov 2, 2013 |
| CVE-2013-1097 | Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allow… | MEDIUM | 4.3 | Jun 17, 2013 |
| CVE-2013-1095 | Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allow… | MEDIUM | 4.3 | Jun 17, 2013 |
| CVE-2013-1094 | Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1… | MEDIUM | 4.3 | Jun 17, 2013 |
| CVE-2013-1093 | Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 1… | MEDIUM | 5.8 | Jun 17, 2013 |
Showing 1 to 25 of 35 CVEs