« Volver al listado

CVE-2012-6534

Estado: ModificadaMedia (4.3)—

Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-6534",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-03-29T16:08:58.353",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2012/Oct/25",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5150932.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=771634",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/21744/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.netiq.com/documentation/novelllogmanager12/readme/data/log_manager1203_readme.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2012/Oct/25",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5150932.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=771634",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/21744/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.netiq.com/documentation/novelllogmanager12/readme/data/log_manager1203_readme.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results \"Save Query As\" \"Save As Retention Policy\" action."
    },
    {
      "lang": "es",
      "value": "Novel Sentinel Log Manager anterior a v1.2.0.3 permite a atacantes remotos crear políticas de retención de datos a través de una petición test/-x-gwt-rpc manipulada para novelllogmanager/datastorageservice.rpc, y permite a los administradores de informes autenticados crear políticas de retención de datos a través de un resultado de búsqueda \"Save Query As\" \"Save As Retention Policy\"."
    }
  ],
  "lastModified": "2026-06-16T23:48:18.800",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A1901D1-CD7E-49F9-BA59-6B04C2018979",
              "versionEndIncluding": "1.2.0.2"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1F04269-CFDB-4209-AB0F-64D8C5E54E30"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.0.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED793BDE-F237-49DA-ACD6-FDD9BDFADAB6"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F30D28A-31FB-4E2D-A2C5-E01C922B4E9D"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23988310-A342-44C2-87B6-C9509DEAFF18"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B16902C-B678-4DAC-B1D4-6B0EF92E71D6"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE4A4F9F-EC22-47F6-A476-D6AB6822B21F"
            },
            {
              "criteria": "cpe:2.3:a:novell:sentinel_log_manager:1.2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D1FC3A1-AF7A-45AF-8337-62FEC7C73643"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}