VYPR
Unrated severityNVD Advisory· Published Mar 29, 2013· Updated Apr 29, 2026

CVE-2013-1080

CVE-2013-1080

Description

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.

Affected products

2
  • cpe:2.3:a:novell:zenworks_configuration_management:10.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:novell:zenworks_configuration_management:10.3:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:zenworks_configuration_management:11.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.