First published: Wed Aug 09 2017(Updated: )
SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus ZENworks Configuration Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0782 is considered a critical vulnerability due to its potential for SQL injection leading to remote code execution.
To fix CVE-2015-0782, update the affected Novell ZENworks Configuration Management software to the latest version provided by the vendor.
CVE-2015-0782 affects users of Novell ZENworks Configuration Management software that implements the ScheduleQuery method.
CVE-2015-0782 allows remote attackers to execute arbitrary SQL commands, which can lead to unauthorized access to the database.
CVE-2015-0782 was publicly disclosed in 2015, highlighting vulnerabilities in Novell's software pertaining to SQL injection.