First published: Wed Aug 09 2017(Updated: )
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus ZENworks Configuration Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0785 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive directories.
To mitigate CVE-2015-0785, users should apply the latest updates and patches provided by Novell for ZENworks Configuration Management.
CVE-2015-0785 can be exploited by remote attackers to read arbitrary files from the server.
CVE-2015-0785 affects Novell ZENworks Configuration Management across multiple versions, so all users should review their installations.
No, user authentication is not required to exploit CVE-2015-0785, which increases the risk of exposure.