CVE-2013-6346: CSRF
Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Novell ZENworks Configuration Management (ZCM)to a version that resolves this vulnerability.Fixed in 11.2.4
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6346?
CVE-2013-6346 is considered a high-severity cross-site request forgery (CSRF) vulnerability affecting Novell ZENworks Configuration Management.
How do I fix CVE-2013-6346?
To fix CVE-2013-6346, upgrade to Novell ZENworks Configuration Management version 11.2.4 or later.
What systems are affected by CVE-2013-6346?
CVE-2013-6346 affects versions of Novell ZENworks Configuration Management prior to 11.2.4 and includes several earlier versions from 10.2 to 11.
What type of attack does CVE-2013-6346 involve?
CVE-2013-6346 involves a cross-site request forgery (CSRF) attack that can hijack user authentication.
What can attackers achieve with CVE-2013-6346?
Attackers can exploit CVE-2013-6346 to perform unauthorized actions on behalf of victims by hijacking their authentication.