CVE-2015-0785: Infoleak
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0785?
CVE-2015-0785 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive directories.
How do I fix CVE-2015-0785?
To mitigate CVE-2015-0785, users should apply the latest updates and patches provided by Novell for ZENworks Configuration Management.
What type of attack can exploit CVE-2015-0785?
CVE-2015-0785 can be exploited by remote attackers to read arbitrary files from the server.
Which version of Novell ZENworks Configuration Management is affected by CVE-2015-0785?
CVE-2015-0785 affects Novell ZENworks Configuration Management across multiple versions, so all users should review their installations.
Is user authentication impacted by CVE-2015-0785?
No, user authentication is not required to exploit CVE-2015-0785, which increases the risk of exposure.