CVE-2013-3706: Path Traversal
Published Mar 6, 2014
·Updated
Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.
Affected Software
1 affected component
Novell ZENworks Configuration Management=11.2
Remediation
Patch Available
Event History
Mar 6, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
via NVD·11:55 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-3706?
CVE-2013-3706 has a medium severity rating as it allows unauthorized file access through directory traversal.
2
How do I fix CVE-2013-3706?
To fix CVE-2013-3706, upgrade to a patched version of Novell ZENworks Configuration Management that addresses this vulnerability.
3
What is the potential impact of CVE-2013-3706?
The potential impact of CVE-2013-3706 includes unauthorized access to sensitive files on the server.
4
Is CVE-2013-3706 exploitable remotely?
Yes, CVE-2013-3706 is exploitable remotely via crafted requests to the PreBoot service.
5
Which software versions are affected by CVE-2013-3706?
CVE-2013-3706 affects Novell ZENworks Configuration Management version 11.2.