CVE-2013-1084Path Traversal in Zenworks Configuration Management

CWE-22Path Traversal3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
4.7%
top 10.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 17

Description

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5x35-7w5r-q6p9: Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 112022-05-17
CVEList
CVE-2013-1084: Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 112013-11-02
CVE-2013-1084 — Path Traversal | cvebase