First published: Wed Feb 10 2016(Updated: )
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ipswitch MOVEit DMZ | <=8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7677 is classified as a medium severity vulnerability due to its ability to allow authenticated users to enumerate file IDs.
To fix CVE-2015-7677, upgrade to Ipswitch MOVEit DMZ version 8.2 or later which addresses this vulnerability.
CVE-2015-7677 affects users of Ipswitch MOVEit DMZ versions prior to 8.2, specifically those using version 8.1 or earlier.
CVE-2015-7677 exploits the MOVEitISAPI service by allowing users to generate different error messages, facilitating FileID enumeration.
CVE-2015-7677 is a remote vulnerability that can be exploited by authenticated users through the MOVEitISAPI interface.