Release date: 2011-09-05
Updated on: 2011-09-05
Affected Systems:
Novell Cloud Manager 1.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-2654
Novell Cloud Manager is a solution for building and managing clouds.
Novell Cloud Manager has a security restriction bypass vulnerability when initializing RPC method objects. Remote attackers can exploit this vulnerability to bypass certain security restrictions.
This vulnerability is caused by an error when initializing an RPC method object. As a result, only some sessions are initialized and a licensed RPC call is executed.
<* Source: 1c239c43f521145fa8417d64a9c32243
Link: http://www.zerodayinitiative.com/advisories/ZDI-11-278/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.novell.com/security-alerts