CVE-2016-1593: Path Traversal
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1593?
CVE-2016-1593 has a medium severity rating due to its potential for arbitrary file upload and execution.
How do I fix CVE-2016-1593?
To fix CVE-2016-1593, upgrade Micro Focus Novell Service Desk to version 7.2 or later to eliminate the vulnerability.
What type of vulnerability is represented by CVE-2016-1593?
CVE-2016-1593 is classified as a directory traversal vulnerability impacting the file upload feature.
Who is affected by CVE-2016-1593?
CVE-2016-1593 affects remote authenticated administrators using Micro Focus Novell Service Desk versions prior to 7.2.
What attack vector is utilized in CVE-2016-1593?
CVE-2016-1593 allows attackers to exploit directory traversal through a multipart/form-data POST request.