CVE-2015-0780

CRITICAL

Novell Zenworks Configuration Management - SQL Injection

Title source: rule

Description

SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Scores

CVSS v3 9.8
EPSS 0.0356
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-89
Status draft

Affected Products (1)

novell/zenworks_configuration_management

Timeline

Published Aug 09, 2017
Tracked Since Feb 18, 2026