Vulnerabilities > Novell > Zenworks Configuration Management > 11.2

DATE CVE VULNERABILITY TITLE RISK
2013-06-17 CVE-2013-1093 Improper Input Validation vulnerability in Novell Zenworks Configuration Management
Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.
network
novell CWE-20
5.8
2013-03-29 CVE-2013-1080 Improper Authentication vulnerability in Novell Zenworks Configuration Management 10.3/11.2
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.
network
low complexity
novell CWE-287
critical
10.0
2013-03-29 CVE-2013-1079 Path Traversal vulnerability in Novell Zenworks Configuration Management
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.
network
novell CWE-22
6.8