CVE-2015-7677: Infoleak
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7677?
CVE-2015-7677 is classified as a medium severity vulnerability due to its ability to allow authenticated users to enumerate file IDs.
How do I fix CVE-2015-7677?
To fix CVE-2015-7677, upgrade to Ipswitch MOVEit DMZ version 8.2 or later which addresses this vulnerability.
Who is affected by CVE-2015-7677?
CVE-2015-7677 affects users of Ipswitch MOVEit DMZ versions prior to 8.2, specifically those using version 8.1 or earlier.
What does CVE-2015-7677 exploit?
CVE-2015-7677 exploits the MOVEitISAPI service by allowing users to generate different error messages, facilitating FileID enumeration.
Is CVE-2015-7677 a remote vulnerability?
CVE-2015-7677 is a remote vulnerability that can be exploited by authenticated users through the MOVEitISAPI interface.