Vulnerability record · CVE-2013-1080 · published 29 March 2013
CVE-2013-1080: Novell ZENworks ZCM web server auth bypass enabling traversal and code execution
Novell · Zenworks Configuration Management
The web server in Novell ZENworks Configuration Management 10.3 and 11.2 before 11.2.4 fails to properly authenticate requests to zenworks/jsp/index.jsp. This lets a remote, unauthenticated attacker bypass authentication, traverse directories, and upload and execute arbitrary programs. Because it is reachable over the network with no credentials, it is a serious pre-auth compromise path for ZCM deployments.
Description
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/jsp/index.jsp, which allows remote attackers to conduct directory traversal attacks, and consequently upload and execute arbitrary programs, via a request to TCP port 443.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10.0 and very high EPSS, plus public exploit code, makes this an urgent patch target.
What it is
The web server in Novell ZENworks Configuration Management 10.3 and 11.2 before 11.2.4 fails to properly authenticate requests to zenworks/jsp/index.jsp. This lets a remote, unauthenticated attacker bypass authentication, traverse directories, and upload and execute arbitrary programs. Because it is reachable over the network with no credentials, it is a serious pre-auth compromise path for ZCM deployments.
Impact
An attacker gains unauthenticated remote code execution on the ZCM server, allowing full control of the host and any managed data or credentials it holds. CVSS 2.0 scores it 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), reflecting complete confidentiality, integrity and availability loss.
Attack surface
Reached over the network via a request to TCP port 443 against the ZCM web server, specifically zenworks/jsp/index.jsp. No authentication is required per the vector (Au:N) and the description; no user interaction is indicated.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.77049 probability, 0.99527 percentile) and public exploit code exists on Exploit-DB (24938), indicating active interest and easy weaponization. No ransomware group usage is documented in the record.
What to do
- Upgrade Novell ZENworks Configuration Management to 11.2.4 or later, which the advisory states fixes the authentication flaw.
- If immediate upgrade is not possible, restrict access to TCP port 443 on ZCM servers to trusted management networks only.
- Review and apply the vendor advisories (Novell KB 7011812 and 7012027) for any interim configuration guidance.
- Audit the ZCM web root and application directories for unexpected files or uploaded content that could indicate prior exploitation.
Detection
- Monitor web server logs for requests to zenworks/jsp/index.jsp with traversal sequences (../) or unusual parameters.
- Alert on file creation or execution in ZCM web-accessible directories, especially new JSP or executable files.
- Watch for outbound connections or process spawning from the ZCM web server process that are not part of normal operation.
- Correlate port 443 access from untrusted source IPs with subsequent file writes or command execution on the ZCM host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1080 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1080), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.