CVE-2013-1084

N/A Unknown
Published: November 02, 2013 Modified: April 29, 2026
View on NVD

Description

Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/55450
Source: cve@mitre.org
Vendor Advisory
http://www.novell.com/support/kb/doc.php?id=7012760
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/55450
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.novell.com/support/kb/doc.php?id=7012027
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/support/kb/doc.php?id=7012760
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

6 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
3.4%
88th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

novell