CVE-2016-1594
22.04.2016, 10:59
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.Enginsight
Vendor | Product | Version |
---|---|---|
novell | service_desk | 𝑥 ≤ 7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References