CVE-2012-6534: Medium severity novell sentinel log manager vulnerability
Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6534?
CVE-2012-6534 has a medium severity rating due to the potential for remote policy creation by attackers.
How do I fix CVE-2012-6534?
To fix CVE-2012-6534, upgrade to Novell Sentinel Log Manager version 1.2.0.3 or later.
Which versions of Novell Sentinel Log Manager are affected by CVE-2012-6534?
Versions of Novell Sentinel Log Manager prior to 1.2.0.3, including 1.0.0.4, 1.1.0.0, 1.1.0.1, 1.1.0.2, 1.2, and 1.2.0.1, are affected by CVE-2012-6534.
What type of attack does CVE-2012-6534 involve?
CVE-2012-6534 involves remote attackers exploiting crafted requests to create unauthorized data retention policies.
Can authenticated users exploit CVE-2012-6534?
Yes, authenticated Report Administrators can also exploit CVE-2012-6534 to create data retention policies via search-results.