CVE-2010-4229
Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and subsequently execute arbitrary code, via directory traversal sequences in a filename field in an upload request.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 25.43% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- novell/zenworks configuration management
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/44120Vendor Advisory
- http://securityreason.com/securityalert/8207
- http://securitytracker.com/id?1025313
- http://www.novell.com/support/viewContent.do?externalId=7007841Vendor Advisory
- http://www.securityfocus.com/archive/1/517425/100/0/threaded
- http://www.securityfocus.com/bid/47295
- http://www.vupen.com/english/advisories/2011/0917Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-11-118/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66656
- http://secunia.com/advisories/44120Vendor Advisory
- http://securityreason.com/securityalert/8207
- http://securitytracker.com/id?1025313
- http://www.novell.com/support/viewContent.do?externalId=7007841Vendor Advisory
- http://www.securityfocus.com/archive/1/517425/100/0/threaded
- http://www.securityfocus.com/bid/47295
- http://www.vupen.com/english/advisories/2011/0917Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-11-118/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66656
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.