Vulnerability record · CVE-2015-0779 · published 7 June 2015
CVE-2015-0779: Novell ZENworks Configuration Management UploadServlet path traversal RCE
Novell · Zenworks Configuration Management
UploadServlet in Novell ZENworks Configuration Management 10 and 11 before 11.3.2 is vulnerable to directory traversal via the uid parameter. A crafted directory name combined with a WAR filename and WAR content in the POST body lets an attacker write a malicious web archive outside the intended upload location, leading to arbitrary code execution.
Description
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323 and CVE-2010-5324.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable path traversal leading to remote code execution with a CVSS 2.0 score of 10 and high EPSS, though no confirmed in-the-wild KEV listing.
What it is
UploadServlet in Novell ZENworks Configuration Management 10 and 11 before 11.3.2 is vulnerable to directory traversal via the uid parameter. A crafted directory name combined with a WAR filename and WAR content in the POST body lets an attacker write a malicious web archive outside the intended upload location, leading to arbitrary code execution.
Impact
An unauthenticated remote attacker can execute arbitrary code on the ZENworks server, gaining full control of the host and any managed endpoints it administers.
Attack surface
Reachable over the network through HTTP requests to UploadServlet; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.745 (99.5th percentile) and public references include a Metasploit pull request, an Exploit-DB entry and a proof-of-concept, indicating mature public exploitation tooling.
What to do
- Upgrade ZENworks Configuration Management to 11.3.2 or later, which fixes the traversal in UploadServlet.
- If immediate upgrade is not possible, restrict network access to the ZENworks server and its UploadServlet endpoint to trusted management networks only.
- Deploy a WAF or reverse proxy rule to block traversal sequences in the uid parameter and unexpected WAR uploads.
- Audit the upload directory and web application paths for unexpected WAR files or modified content.
- Monitor vendor advisory 7016419 for any additional guidance.
Detection
- Inspect HTTP POST requests to UploadServlet for traversal sequences (../, encoded variants) in the uid parameter.
- Alert on WAR file uploads or WAR content appearing in POST bodies to ZENworks endpoints.
- Monitor the ZENworks upload and web directories for newly created or modified WAR files outside expected paths.
- Review server logs for anomalous requests to UploadServlet from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0779 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0779), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.