HTTP: Novell ZENworks Configuration Management schedule.ScheduleQuery SQL Injection

An SQL injection vulnerability exists in ZENworks Configuration Management. The vulnerability is due to insufficient sanitization of a request parameter in the run method of the ScheduleQuery class before using the parameter in SQL queries. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted message to a target server to execute arbitrary SQL code. This signature detects attempts to exploit a known vulnerability against ZENworks Configuration Management. A successful exploit can lead to Arbitrary SQL code execution.

Extended Description

SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected Products

Novell zenworks_configuration_management

References

CVE: CVE-2015-0782

Short Name
HTTP:SQL:NOVEL-ZENWORKS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-0782 Configuration Injection Management Novell SQL ZENworks schedule.ScheduleQuery
Release Date
06/29/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3494
False Positive
Unknown
Vendors

Novell

CVSS Score

7.5

Found a potential security threat?