Novell Zenworks Remote Information Leakage (CVE-2015-0785)
Novell Zenworks Remote Information Leakage (CVE-2015-0785)
Release date:
Updated on:
Affected Systems:
Novell ZENworks
Description:
Bugtraq id: 74288
CVE (CAN) ID: CVE-2015-0785
Novell ZENworks Configuration Management is a Configuration Management solution in the ZENworks System gateway tool.
Novell Zenworks has a security vulnerability in the implementation of com. novell. zenworks. inventory. rtr. actionclasses. wcreports. Attackers can exploit this vulnerability to obtain sensitive information. This vulnerability is caused by an error in filtering the "dirname" variable path.
<* Source: anonymous
Link: http://www.zerodayinitiative.com/advisories/ZDI-15-152/
*>
Suggestion:
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.novell.com/support/kb/doc.php? Id = 7016431
This article permanently updates the link address: