CVE-2016-5754: Infoleak
Published Mar 23, 2017
·Updated
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
Affected Software
5 affected components
NetIQ Access Manager=4.1
NetIQ Access Manager=4.1-sp1
NetIQ Access Manager=4.1-sp2
NetIQ Access Manager=4.2
NetIQ Access Manager=4.2-sp1
Event History
Mar 23, 2017
CVE Published
via MITRE·06:36 AM
Data Sourced
via MITRE·06:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-5754?
CVE-2016-5754 is classified as a moderate severity vulnerability due to the potential information leakage from .htaccess files.
2
How do I fix CVE-2016-5754?
To fix CVE-2016-5754, upgrade to NetIQ Access Manager versions 4.1.2 Hot Fix 1 or 4.2 SP2 or later.
3
What software is affected by CVE-2016-5754?
CVE-2016-5754 affects NetIQ Access Manager versions 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
4
What is the impact of CVE-2016-5754?
The impact of CVE-2016-5754 may include unauthorized access to sensitive information due to .htaccess file exposure.
5
Is CVE-2016-5754 remotely exploitable?
CVE-2016-5754 is potentially exploitable remotely if the conditions are met for accessing the vulnerable .htaccess files.