Vulnerabilities > Novell > Zenworks Configuration Management > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-25 | CVE-2012-6344 | Cross-site Scripting vulnerability in Novell Zenworks Configuration Management Novell ZENworks Configuration Management before 11.2.4 allows XSS. | 6.1 |
2017-08-09 | CVE-2015-0783 | Information Exposure vulnerability in Novell Zenworks Configuration Management The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable. | 6.5 |
2016-02-18 | CVE-2015-5970 | Code Injection vulnerability in Novell Zenworks Configuration Management The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference. | 5.3 |