Vulnerability record · CVE-2011-2653 · published 8 December 2011
CVE-2011-2653: Novell ZENworks Asset Management rtrlet directory traversal enables remote code execution
Novell · Zenworks Asset Management
The rtrlet component in Novell ZENworks Asset Management 7.5 is vulnerable to directory traversal (CWE-22), allowing a remote attacker to upload an executable file outside the intended directory and execute arbitrary code. The flaw is network-reachable and, per the CVSS 2.0 vector, requires no authentication or user interaction, making it a severe pre-auth code execution issue for exposed deployments.
Description
Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary code execution with a CVSS 2.0 base score of 10.0 and very high EPSS probability warrants critical priority.
What it is
The rtrlet component in Novell ZENworks Asset Management 7.5 is vulnerable to directory traversal (CWE-22), allowing a remote attacker to upload an executable file outside the intended directory and execute arbitrary code. The flaw is network-reachable and, per the CVSS 2.0 vector, requires no authentication or user interaction, making it a severe pre-auth code execution issue for exposed deployments.
Impact
An unauthenticated remote attacker can write and execute arbitrary code on the affected server, gaining full control of confidentiality, integrity and availability (CVSS 2.0 base 10.0).
Attack surface
Reached over the network through the rtrlet component; the AV:N/AC:L/Au:N vector indicates no authentication and no user interaction are required. The description does not specify the exact endpoint or upload path.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.72493, 99.4th percentile), indicating elevated likelihood of exploitation activity. Reference tags are empty, so no exploit code or in-the-wild confirmation can be cited from this record.
What to do
- Apply the vendor fix referenced in the Novell download link for ZENworks Asset Management 7.5.
- Restrict network access to the rtrlet component and ZAM management interfaces to trusted hosts only.
- If patching is delayed, disable or block the rtrlet upload functionality until the fix is in place.
- Run the ZAM service with least privilege and ensure upload directories are not executable.
- Monitor and alert on unexpected executable files appearing in web-accessible or upload directories.
Detection
- Review web and application logs for rtrlet requests containing traversal sequences such as ../ or encoded variants.
- Alert on executable files (.exe, .dll, .jsp, .war) written to upload or web directories by the ZAM service account.
- Monitor for unexpected child processes spawned by the ZAM/rtrlet service.
- Baseline and integrity-monitor files in ZAM installation and upload paths for unauthorized additions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-2653 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-2653), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.