VYPR
Unrated severityNVD Advisory· Published Jun 7, 2015· Updated May 6, 2026

CVE-2015-0779

CVE-2015-0779

Description

Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323 and CVE-2010-5324.

Affected products

6
  • cpe:2.3:a:novell:zenworks_configuration_management:11:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:novell:zenworks_configuration_management:11:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:zenworks_configuration_management:11.2:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:zenworks_configuration_management:11.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:zenworks_configuration_management:11.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:zenworks_configuration_management:11.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:zenworks_configuration_management:11:sp1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.