Information Disclosure Vulnerability in Micro Focus Novell Service Desk
CVE-2016-1594
6.5MEDIUM
What is CVE-2016-1594?
An information disclosure vulnerability in Micro Focus Novell Service Desk prior to version 7.2 permits remote authenticated users to access arbitrary attachments. This is accomplished through crafted requests to a LiveTime.woa URL, which may involve actions such as downloadLogFiles or downloadFile. As a consequence, sensitive information can be inadvertently exposed to malicious actors.