CVE-2015-0779: Path Traversal
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323 and CVE-2010-5324.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0779?
CVE-2015-0779 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2015-0779?
To mitigate CVE-2015-0779, upgrade Novell ZENworks Configuration Management to version 11.3.2 or later.
Which versions of Novell ZENworks Configuration Management are affected by CVE-2015-0779?
CVE-2015-0779 affects versions 10 and 11 of Novell ZENworks Configuration Management prior to 11.3.2.
What type of attack is facilitated by CVE-2015-0779?
CVE-2015-0779 facilitates directory traversal attacks that can lead to arbitrary code execution.
Is there a workaround for CVE-2015-0779 if I cannot upgrade?
There are no documented workarounds for CVE-2015-0779, so upgrading to a patched version is recommended.