Release date: 2013-03-22
Updated on: 2013-03-26
Affected Systems:
Novell ZENworks Control Center
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58668
CVE (CAN) ID: CVE-2013-1080
Novell ZENworks Configuration Management is a Configuration Management solution in the ZENworks System gateway tool.
By default, Novell ZENworks Control Center listens to TCP443, which does not have sufficient authentication checks for/zenworks/jsp/index. jsp. This allows remote attackers to upload files to webserver. Combined with the directory traversal vulnerability, attackers can exploit this condition to execute remote code with system-level permissions.
<* Source: James Burton Insomnia Security
Link: http://www.zerodayinitiative.com/advisories/ZDI-13-049/
Http://www.novell.com/support/kb/doc.php? Id = 7011812
Http://secunia.com/advisories/52784/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.novell.com/security-alerts