CVE-2015-5970: Code Injection
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5970?
CVE-2015-5970 has been classified as a medium severity vulnerability due to its potential for remote exploitation through XPath injection.
How do I fix CVE-2015-5970?
To fix CVE-2015-5970, it is recommended to upgrade Novell ZENworks Configuration Management to the latest version that addresses this vulnerability.
What systems are affected by CVE-2015-5970?
CVE-2015-5970 affects Novell ZENworks Configuration Management versions 11.3.0, 11.3.1, 11.3.2, 11.4.0, and 11.4.1.
What kind of attacks can be executed through CVE-2015-5970?
CVE-2015-5970 allows remote attackers to conduct XPath injection attacks and potentially read arbitrary text files.
Is there a workaround for CVE-2015-5970?
Currently, there are no documented workarounds for CVE-2015-5970, so the best approach is to apply the necessary updates.