Security Advisory

CVE-2015-5970

5.3
MEDIUM

Vulnerability Description

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
Published Date February 18, 2016
Official Source NIST NVD Advisory