Novell ZENworks Patch Management Server SQL injection
2 Nov. 2005
Summary
ZENworks Suite "automates and enforces business and IT managment processes across the lifecycle of desktops, laptops, servers and handhelds to control costs, ensure security and compliance, optimize the value of IT assets across diverse server and client platforms".
The Novell ZENworks Patch Management Server is vulnerable to SQL injection in the management console.
Server 'testclient' is not configured for DATA ACCESS.
Solution:
Upgrade to ZENworks Patch Management version 6.2.2.181 (or newer hot fix via your PLUS server) found at http://download.novell.com.
Timeline of public disclosure:
01-10-2005 Vulnerability discovered
11-10-2005 Research completed
12-10-2005 Sent information to Novell (secure@novell.com)
12-10-2005 Information sent to CERT/CC (cert@cert.org)
12-10-2005 CERT/CC responds with VU#536300
13-10-2005 Response from Novell
27-10-2005 Public Release