TippingPoint Zero Day Initiative
 

Novell ZENworks Reporting Appliance Directory Traversal Arbitrary File Creation Vulnerability

ZDI-17-410: June 14th, 2017

CVSS Score

Affected Vendors

Affected Products

    ZENworks Reporting Appliance

Vulnerability Details


This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of Novell ZENworks Reporting Appliance. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the FCExporter servlet. The process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute arbitrary code under the context of the web server process.

Vendor Response

Novell states:


Micro Focus shipped a fix for this issue in ZENworks reporting v6.2.1 in January 2017.


Disclosure Timeline

    2016-07-29 - Vulnerability reported to vendor
    2017-06-14 - Coordinated public release of advisory

Credit

This vulnerability was discovered by:
    rgod