CVE-2013-6344: XSS
The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Novell ZENworks Configuration Management (ZCM) - ZCC pageto a version that resolves this vulnerability.Fixed in 11.2.4
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6344?
CVE-2013-6344 has a medium severity rating as it allows for cross-frame scripting attacks.
How do I fix CVE-2013-6344?
To fix CVE-2013-6344, upgrade to Novell ZENworks Configuration Management version 11.2.4 or later.
What does CVE-2013-6344 affect?
CVE-2013-6344 affects various versions of Novell ZENworks Configuration Management, including versions up to 11.2.3 and several 10.x versions.
What type of attack can be performed using CVE-2013-6344?
CVE-2013-6344 allows attackers to conduct cross-frame scripting attacks on vulnerable ZENworks applications.
Is there a workaround for CVE-2013-6344?
There are no known workarounds for CVE-2013-6344; upgrading to the fixed version is recommended.