Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As Retention Policy" action.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-03-29 09:08
Updated : 2017-10-04 18:29
NVD link : CVE-2012-6534
Mitre link : CVE-2012-6534
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
novell
- sentinel_log_manager