← Vulnerability feed

Vulnerability record · CVE-2013-1080 · published 29 March 2013

CVE-2013-1080: Novell ZENworks ZCM web server auth bypass enabling traversal and code execution

Novell · Zenworks Configuration Management

The web server in Novell ZENworks Configuration Management 10.3 and 11.2 before 11.2.4 fails to properly authenticate requests to zenworks/jsp/index.jsp. This lets a remote, unauthenticated attacker bypass authentication, traverse directories, and upload and execute arbitrary programs. Because it is reachable over the network with no credentials, it is a serious pre-auth compromise path for ZCM deployments.

10.0 CVSS 2.0 High EPSS 77% · top 0.5% CWE-287 · Improper authentication
10.0CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10.0 and very high EPSS, plus public exploit code, makes this an urgent patch target.

What it is

The web server in Novell ZENworks Configuration Management 10.3 and 11.2 before 11.2.4 fails to properly authenticate requests to zenworks/jsp/index.jsp. This lets a remote, unauthenticated attacker bypass authentication, traverse directories, and upload and execute arbitrary programs. Because it is reachable over the network with no credentials, it is a serious pre-auth compromise path for ZCM deployments.

Impact

An attacker gains unauthenticated remote code execution on the ZCM server, allowing full control of the host and any managed data or credentials it holds. CVSS 2.0 scores it 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), reflecting complete confidentiality, integrity and availability loss.

Attack surface

Reached over the network via a request to TCP port 443 against the ZCM web server, specifically zenworks/jsp/index.jsp. No authentication is required per the vector (Au:N) and the description; no user interaction is indicated.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.77049 probability, 0.99527 percentile) and public exploit code exists on Exploit-DB (24938), indicating active interest and easy weaponization. No ransomware group usage is documented in the record.

What to do

  • Upgrade Novell ZENworks Configuration Management to 11.2.4 or later, which the advisory states fixes the authentication flaw.
  • If immediate upgrade is not possible, restrict access to TCP port 443 on ZCM servers to trusted management networks only.
  • Review and apply the vendor advisories (Novell KB 7011812 and 7012027) for any interim configuration guidance.
  • Audit the ZCM web root and application directories for unexpected files or uploaded content that could indicate prior exploitation.

Detection

  • Monitor web server logs for requests to zenworks/jsp/index.jsp with traversal sequences (../) or unusual parameters.
  • Alert on file creation or execution in ZCM web-accessible directories, especially new JSP or executable files.
  • Watch for outbound connections or process spawning from the ZCM web server process that are not part of normal operation.
  • Correlate port 443 access from untrusted source IPs with subsequent file writes or command execution on the ZCM host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1080 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed10.0CVE-2015-0779Novell ZENworks Configuration Management UploadServlet path traversal RCEUploadServlet in Novell ZENworks Configuration Management 10 and 11 before 11.3.2 is vulnerable to directory traversal via the uid parameter. A craft…EPSS 74%analysed10.0CVE-2010-5324Novell ZENworks Configuration Management UploadServlet path traversal RCEUploadServlet in the Remote Management component of Novell ZENworks Configuration Management 10 before 10.3 is vulnerable to directory traversal via …EPSS 72%analysed10.0CVE-2010-5323Novell zenworks configuration management path traversal vulnerabilityDirectory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.…EPSS 14%10.0CVE-2013-6345Novell zenworks configuration management vulnerabilityUnspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors relat…EPSS 1.5%10.0CVE-2011-3175Novell ZENworks Preboot Service stack buffer overflow via opcode 0x6cThe Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a contains a stack-based buffer overflow (CWE-119) triggered by an…EPSS 66%analysed10.0CVE-2011-3176Novell ZENworks Preboot Service stack buffer overflowThe Preboot Service in Novell ZENworks Configuration Management 11.1 and 11.1a contains a stack-based buffer overflow reachable through an opcode 0x4…EPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1080), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.