Show filters
61 Total Results
Displaying 1-10 of 61
Sort by:
Attacker Value
Very High

CVE-2014-6271

Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Attacker Value
Unknown

Novell ZENworks Admin Studio ISProxy Vulnerability

Disclosure Date: March 29, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in the ISCreateObject method in an ActiveX control in InstallShield\ISProxy.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.3 through 11.2 allows remote attackers to execute arbitrary local DLL files via a crafted web page that also calls the Initialize method.
0
Attacker Value
Unknown

CVE-2023-6400

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4.
0
Attacker Value
Unknown

CVE-2022-38757

Disclosure Date: December 23, 2022 (last updated October 08, 2023)
A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside the scope of the administrator. This vulnerability does not result in the administrators gaining additional rights on the managed devices, either in the scope or outside the scope of the administrator.
Attacker Value
Unknown

CVE-2021-22521

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.
Attacker Value
Unknown

CVE-2012-6344

Disclosure Date: January 25, 2020 (last updated February 21, 2025)
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
Attacker Value
Unknown

CVE-2012-6345

Disclosure Date: January 25, 2020 (last updated November 28, 2024)
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
Attacker Value
Unknown

CVE-2015-0785

Disclosure Date: August 09, 2017 (last updated November 08, 2023)
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
0
Attacker Value
Unknown

CVE-2015-0781

Disclosure Date: August 09, 2017 (last updated November 08, 2023)
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-0780

Disclosure Date: August 09, 2017 (last updated November 08, 2023)
SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0