Security Advisory
CVE-2015-5970
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.