CVE-2015-5970

MEDIUM

Novell ZENworks <11.4 - XPath Injection

Title source: llm

Description

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.

Scores

CVSS v3 5.3
EPSS 0.0052
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-94
Status draft

Affected Products (5)

novell/zenworks_configuration_management
novell/zenworks_configuration_management
novell/zenworks_configuration_management
novell/zenworks_configuration_management
novell/zenworks_configuration_management

Timeline

Published Feb 18, 2016
Tracked Since Feb 18, 2026