APP: Novell ZENworks Configuration Management File Upload Directory Traversal

This signature detects attempts to exploit a known vulnerability in Novell ZENworks Configuration Management. It is due to insufficient input validation within the ZENworks Server's FileUploadServlet. Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the vulnerable system with the privileges of the Administrator user.

Extended Description

Novell ZENworks Configuration Management is prone to a remote code-execution vulnerability. An attacker can exploit this issue to execute arbitrary code in the context of the 'ZenWorks' user. Successful attacks will completely compromise the affected computer. Failed attacks will likely cause denial-of-service conditions. ZENworks Configuration Management versions prior to 10.3.2 are vulnerable.

Affected Products

Novell zenworks_configuration_management

References

BugTraq: 39914 47295

CVE: CVE-2010-4229

Short Name
APP:NOVELL:ZENWORKS-DIR-TRVRS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2010-4229 CVE-2010-5324 Configuration Directory File Management Novell Traversal Upload ZENworks bid:39914 bid:47295
Release Date
06/15/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Novell

CVSS Score

10.0

Found a potential security threat?