5
CVSSv2

CVE-2015-5970

Published: 18/02/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote malicious users to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.

Vulnerable Product Search on Vulmon Subscribe to Product

novell zenworks configuration management 11.4.0

novell zenworks configuration management 11.3.2

novell zenworks configuration management 11.3.1

novell zenworks configuration management 11.3.0

novell zenworks configuration management 11.4.1