CVE-2016-1595
22.04.2016, 10:59
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.Enginsight
Vendor | Product | Version |
---|---|---|
novell | service_desk | 𝑥 ≤ 7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References