Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell Sentinel Log Manager 权限许可和访问控制漏洞
Vulnerability Description
Novell Sentinel Log Manager是一个日志管理软件。 Novell Sentinel Log Manager 1.2.0.3之前版本中存在漏洞。通过特制的text/x-gwt-rpc请求发送到novelllogmanager/datastorageservice.rpc,远程攻击者利用该漏洞创建数据保留策略。通过搜索结果‘Save Query As’,‘Save As Retention Policy’操作,远程认证的Report Administrators创建数据保留策略。
CVSS Information
N/A
Vulnerability Type
N/A