CVE-2015-5970

Publication date

2016-02-18 22:00:00

Family

microfocus

State

PUBLISHED

Description

The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.