← All CVEs

CVE-2013-1080

high · 10

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.

10
CVSS
77.0%
EPSS (exploit prob.)
100th
EPSS percentile
2013-03-29
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
novellzenworks_configuration_management10.3
novellzenworks_configuration_management11.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1080