CVE-2015-5970

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
microfocusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
VendorProductVersion
novellzenworks_configuration_management
11.3.0
novellzenworks_configuration_management
11.3.1
novellzenworks_configuration_management
11.3.2
novellzenworks_configuration_management
11.4.0
novellzenworks_configuration_management
11.4.1
𝑥
= Vulnerable software versions