CVE-2013-1084: Path Traversal
Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1084?
CVE-2013-1084 has a medium severity rating due to its ability to allow remote file access.
How do I fix CVE-2013-1084?
To remediate CVE-2013-1084, ensure that you upgrade to a patched version of Novell ZENworks Configuration Management beyond 11.2.3.
What is the impact of CVE-2013-1084?
The impact of CVE-2013-1084 is that an attacker can read arbitrary files on the server, potentially leading to sensitive data exposure.
Who is affected by CVE-2013-1084?
CVE-2013-1084 affects users of Novell ZENworks Configuration Management version 11.2.3.
What is the nature of the vulnerability in CVE-2013-1084?
CVE-2013-1084 is a directory traversal vulnerability that allows unauthorized file access through manipulated inputs.