CVE-2015-0784: Infoleak
Published Aug 9, 2017
·Updated
Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable.
Affected Software
1 affected component
Novell ZENworks Configuration Management
Event History
Aug 9, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0784?
CVE-2015-0784 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-0784?
To remediate CVE-2015-0784, update to the latest version of Novell ZENworks Configuration Management.
3
What type of attack does CVE-2015-0784 allow?
CVE-2015-0784 allows remote attackers to obtain Session IDs of logged-in users.
4
Which software is affected by CVE-2015-0784?
CVE-2015-0784 affects Novell ZENworks Configuration Management.
5
Is CVE-2015-0784 a local or remote vulnerability?
CVE-2015-0784 is a remote vulnerability.