Novell ZENworks Configuration Management File Overwrite Vulnerability
Last Update Date:
12 Apr 2011 12:11
Release Date:
12 Apr 2011
6135
Views
RISK: Medium Risk
TYPE: Operating Systems - Others OS
A vulnerability has been identified in Novell ZENworks Configuration Management, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error related to specific transversal file modifications, which could allow attackers to execute arbitrary code via an inventory service.
Impact
- Remote Code Execution
System / Technologies affected
- Novell ZENworks Configuration Management versions prior to 10.3.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Novell ZENworks Configuration Management version 10.3.2 :
http://www.novell.com/support
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with