Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell ZENworks Configuration Management 安全漏洞
Vulnerability Description
Novell ZENworks Configuration Management(ZCM)是美国Novell公司的一套配置管理解决方案。该方案可借助集成工具,在物理、虚拟和云环境中实现IT管理和业务流程的自动化。 Novell ZCM 11.3版本和11.4版本的ChangePassword RPC方法中存在安全漏洞。远程攻击者可借助恶意的查询利用该漏洞实施Xpath注入攻击,读取任意文本文件。
CVSS Information
N/A
Vulnerability Type
N/A