CVE-2015-5970

MEDIUM

Novell ZENworks <11.4 - XPath Injection

Title source: llm
STIX 2.1

Description

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-16-167
Vendor Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7017240

Scores

CVSS v3 5.3
EPSS 0.0052
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-94
Status published
Products (5)
novell/zenworks_configuration_management 11.3.0
novell/zenworks_configuration_management 11.3.1
novell/zenworks_configuration_management 11.3.2
novell/zenworks_configuration_management 11.4.0
novell/zenworks_configuration_management 11.4.1
Published Feb 18, 2016
Tracked Since Feb 18, 2026