CVE-2010-4229
Last modified
CVE-2010-4229 is a vulnerability of currently unknown severity. Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and subsequently execute arbitrary code, via directory traversal sequences in a filename field in an upload request.. EPSS estimates a 25.43% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and subsequently execute arbitrary code, via directory traversal sequences in a filename field in an upload request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Novell | Zenworks Configuration Management | 10.3 |
| Novell | Zenworks Configuration Management | 10.3.1 |
| Novell | Zenworks Configuration Management | 11 |
References
- http://secunia.com/advisories/44120Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0917Vendor Advisory
- http://secunia.com/advisories/44120Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0917Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4229?
How severe is CVE-2010-4229?
How do I fix CVE-2010-4229?
Are you affected by CVE-2010-4229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
