Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results Save Query As Save As Retention Policy action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sentinel_log_manager | Novell | * | 1.2.0.2 (including) |
Sentinel_log_manager | Novell | 1.0.0.4 (including) | 1.0.0.4 (including) |
Sentinel_log_manager | Novell | 1.0.0.5 (including) | 1.0.0.5 (including) |
Sentinel_log_manager | Novell | 1.1.0.0 (including) | 1.1.0.0 (including) |
Sentinel_log_manager | Novell | 1.1.0.1 (including) | 1.1.0.1 (including) |
Sentinel_log_manager | Novell | 1.1.0.2 (including) | 1.1.0.2 (including) |
Sentinel_log_manager | Novell | 1.2 (including) | 1.2 (including) |
Sentinel_log_manager | Novell | 1.2.0.1 (including) | 1.2.0.1 (including) |