Total vulnerabilities in the database
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
Software | From | Fixed in |
---|---|---|
novell / zenworks_configuration_management | 11.4.0 | 11.4.0.x |
novell / zenworks_configuration_management | 11.3.2 | 11.3.2.x |
novell / zenworks_configuration_management | 11.3.1 | 11.3.1.x |
novell / zenworks_configuration_management | 11.3.0 | 11.3.0.x |
novell / zenworks_configuration_management | 11.4.1 | 11.4.1.x |