Lucene search

K
cve[email protected]CVE-2010-4229
HistoryApr 18, 2011 - 6:55 p.m.

CVE-2010-4229

2011-04-1818:55:00
CWE-22
web.nvd.nist.gov
33
cve-2010-4229
directory traversal
vulnerability
zenworks asset management
novell
zam
configuration management

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.903 High

EPSS

Percentile

98.8%

Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and subsequently execute arbitrary code, via directory traversal sequences in a filename field in an upload request.

Affected configurations

NVD
Node
novellzenworks_configuration_managementMatch10.3
OR
novellzenworks_configuration_managementMatch10.3.1
OR
novellzenworks_configuration_managementMatch11

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.903 High

EPSS

Percentile

98.8%