CVE-2016-1595: Infoleak
Published Apr 22, 2016
·Updated
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
Affected Software
1 affected component
Novell Service Desk<=7.1
Event History
Apr 22, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1595?
CVE-2016-1595 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-1595?
To fix CVE-2016-1595, upgrade Novell Service Desk to version 7.2 or later.
3
What type of attack is possible with CVE-2016-1595?
CVE-2016-1595 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks.
4
What information can be leaked due to CVE-2016-1595?
CVE-2016-1595 can lead to the exposure of sensitive information through compromised database queries.
5
Which versions of Novell Service Desk are affected by CVE-2016-1595?
CVE-2016-1595 affects Novell Service Desk versions prior to 7.2.