CVE-2013-1080

critical
Published 2013-03-29 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.novell.com/support/kb/doc.php?id=7011812

Application impact

VendorProductVersionsFixed
novellzenworks_configuration_management10.3
novellzenworks_configuration_management11.2

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.