Advisory Details

June 14th, 2017

Novell ZENworks Reporting Appliance Directory Traversal Arbitrary File Creation Vulnerability

ZDI-17-410
ZDI-CAN-3879

CVE ID
CVSS SCORE 6.8, (AV:N/AC:M/Au:N/C:P/I:P/A:P)
AFFECTED VENDORS Novell
AFFECTED PRODUCTS ZENworks Reporting Appliance
VULNERABILITY DETAILS


This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of Novell ZENworks Reporting Appliance. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the FCExporter servlet. The process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code under the context of the web server process.

VENDOR RESPONSE Novell states:


Micro Focus shipped a fix for this issue in ZENworks reporting v6.2.1 in January 2017.


DISCLOSURE TIMELINE
  • 2016-07-29 - Vulnerability reported to vendor
  • 2017-06-14 - Coordinated public release of advisory
CREDIT rgod
BACK TO ADVISORIES