Novell Zenworks SQL injection vulnerability in CVE-2015-0780)
Novell Zenworks SQL injection vulnerability in CVE-2015-0780)
Release date:
Updated on:
Affected Systems:
Novell ZENworks
Description:
Bugtraq id: 74284
CVE (CAN) ID: CVE-2015-0780
Novell ZENworks Configuration Management is a Configuration Management solution in the ZENworks System gateway tool.
Novell Zenworks has a security vulnerability in the implementation of the GetReRequestData method in the GetStoredResult class. Attackers can exploit this vulnerability to execute arbitrary code in the database context.
<* Source: anonymous
Link: http://www.zerodayinitiative.com/advisories/ZDI-15-147/
*>
Suggestion:
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.novell.com/support/kb/doc.php? Id = 7016431
This article permanently updates the link address: