Novell Sentinel Log Manager Unauthorized Access Vulnerability
BID:55767
Info
Novell Sentinel Log Manager Unauthorized Access Vulnerability
| Bugtraq ID: | 55767 |
| Class: | Design Error |
| CVE: |
CVE-2012-6534 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2012 12:00AM |
| Updated: | Apr 01 2013 12:27PM |
| Credit: | Piotr |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Novell Sentinel Log Manager Unauthorized Access Vulnerability
Sentinel Log Manager is prone to an unauthorized-access vulnerability.
Successful exploits may allow an attacker to configure the retention policies without proper authentication; this may aid in further attacks.
Sentinel Log Manager 1.2.0.2 and prior are vulnerable.
Sentinel Log Manager is prone to an unauthorized-access vulnerability.
Successful exploits may allow an attacker to configure the retention policies without proper authentication; this may aid in further attacks.
Sentinel Log Manager 1.2.0.2 and prior are vulnerable.
Exploit / POC
Novell Sentinel Log Manager Unauthorized Access Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
Novell Sentinel Log Manager Unauthorized Access Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Novell Sentinel Log Manager Unauthorized Access Vulnerability
References:
References:
- Sentinel Log Manager Homepage (Novell)