| Vulnerability Name: | CVE-2012-2215 (CCN-74189) | ||||||||
| Assigned: | 2012-03-20 | ||||||||
| Published: | 2012-03-20 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to read arbitrary files via an opcode 0x21 request. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-22 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2012-2215 Source: CONFIRM Type: Patch http://download.novell.com/Download?buildid=rs4B5jhWKf8~ Source: CCN Type: SA48501 Novell ZENworks Configuration Management Multiple Vulnerabilities Source: CCN Type: Novell Document ID 5127930 ZCM 11.1/11.1a fix for PreBoot Service Vulnerabilities - see TID 7009969, TID 7009970 and TID 7009971 Source: CONFIRM Type: Patch http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5127930.html Source: CCN Type: Novell Document ID: 7010044 ZENworks Configuration Management 11.2 - update information and list of fixes Source: CONFIRM Type: UNKNOWN http://www.novell.com/support/viewContent.do?externalId=7010044 Source: CCN Type: OSVDB ID: 80230 Novell ZENworks Configuration Management Preboot Service 0x21 Opcode Request Parsing Arbitrary File Access Source: CCN Type: BID-52659 Novell ZENworks Configuration Management Multiple Security Vulnerabilities Source: IDEFENSE Type: UNKNOWN 20120314 Novell ZENworks Configuration Management PreBoot Service Opcode 0x21 Arbitrary File Download Vulnerability Source: XF Type: UNKNOWN zenworks-preboot-file-download(74189) Source: XF Type: UNKNOWN zenworks-preboot-file-download(74189) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||