{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Novell ZENworks Patch Management versions 6.2 et ant\u00e9rieures.","product":{"name":"N/A","vendor":{"name":"Novell","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nPlusieurs variables insuffisament prot\u00e9g\u00e9es dans l'une des pages web du\nserveur permettent l'injection de commandes SQL.\n\n## Solution\n\nLa version 6.3.2.700 de Novell ZENworks Patch Management corrige le\nprobl\u00e8me. Se r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour\nl'obtention des correctifs (cf. section Documentation).\n","cves":[],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 Novell 3506963 du 05 d\u00e9cembre 2006 :","url":"http://secure-support.novell.com/KanisaPlatform/Publishing/298/3506963_f.SAL_Public.html"}],"reference":"CERTA-2006-AVI-531","revisions":[{"description":"version initiale.","revision_date":"2006-12-06T00:00:00.000000"}],"risks":[{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"}],"summary":"Une vuln\u00e9rabilit\u00e9 pr\u00e9sente dans Novell ZENworks Patch Management permet\nl'injection de directives SQL.\n","title":"Vuln\u00e9rabilit\u00e9 dans Novell ZENworks Patch Management","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Novell du 05 d\u00e9cembre 2006","url":null}]}
