CVE-2013-1093: Input Validation
Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1093?
CVE-2013-1093 has a medium severity rating due to its potential for phishing attacks.
How do I fix CVE-2013-1093?
To fix CVE-2013-1093, update to Novell ZENworks Configuration Management version 11.2.3a Monthly Update 1 or later.
What type of vulnerability is CVE-2013-1093?
CVE-2013-1093 is classified as an open redirect vulnerability.
What versions of Novell ZENworks are affected by CVE-2013-1093?
CVE-2013-1093 affects Novell ZENworks Configuration Management versions 11.2, 11.2.1, 11.2.2, and 11.2.3 before the update.
Can CVE-2013-1093 be exploited remotely?
Yes, CVE-2013-1093 can be exploited remotely to redirect users to arbitrary websites.