HTTP: Novell ZENworks Configuration Management GetStoredResult.class SQL Injection

This signature detects attempts to exploit a known vulnerability against ZENworks Configuration Management.A successful attack can lead to access of sensitive information.

Extended Description

SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected Products

Novell zenworks_configuration_management

References

CVE: CVE-2015-0780

Short Name
HTTP:SQL:NOVELL-ZENWORKS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-0780 Configuration GetStoredResult.class Injection Management Novell SQL ZENworks
Release Date
05/06/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Novell

CVSS Score

7.5

Found a potential security threat?