CVE-2011-2654
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.63% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- novell/cloud manager
- Source
- cve@mitre.org
References
- http://download.novell.com/Download?buildid=NSONlV5PqMo~
- http://secunia.com/advisories/45845Vendor Advisory
- http://www.securityfocus.com/bid/49432
- http://www.securitytracker.com/id?1026006
- http://zerodayinitiative.com/advisories/ZDI-11-278/
- http://download.novell.com/Download?buildid=NSONlV5PqMo~
- http://secunia.com/advisories/45845Vendor Advisory
- http://www.securityfocus.com/bid/49432
- http://www.securitytracker.com/id?1026006
- http://zerodayinitiative.com/advisories/ZDI-11-278/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.