CVE-2016-1594
Last modified
CVE-2016-1594 is a vulnerability of currently unknown severity. Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.. EPSS estimates a 6.90% chance of exploitation in the next 30 days.
Description
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Novell | Service Desk | <= 7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1594?
How severe is CVE-2016-1594?
How do I fix CVE-2016-1594?
Are you affected by CVE-2016-1594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
