Novell Service Desk vulnerabilities
4 known vulnerabilities affecting novell/service_desk.
Total CVEs
4
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2016-1593HIGHCVSS 7.2PoC≤ 7.12016-04-22
CVE-2016-1593 [HIGH] CWE-22 CVE-2016-1593: Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk bef
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.
nvd
CVE-2016-1594MEDIUMCVSS 6.5PoC≤ 7.12016-04-22
CVE-2016-1594 [MEDIUM] CWE-200 CVE-2016-1594: Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attac
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
nvd
CVE-2016-1595MEDIUMCVSS 6.5PoC≤ 7.12016-04-22
CVE-2016-1595 [MEDIUM] CWE-200 CVE-2016-1595: LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk b
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
nvd
CVE-2016-1596MEDIUMCVSS 5.4PoC≤ 7.12016-04-22
CVE-2016-1596 [MEDIUM] CWE-79 CVE-2016-1596: Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 al
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (
nvd