← Back

CVE-2016-0899

nvd nist
Published: Jul 4, 2016Modified: May 6, 2026

JSON object

Loading...
6.3
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 4.0
Source: NVD

Description

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.

Affected (5)

Products: Emc: Rsa Archer Egrc
1 product
Rsa Archer Egrc
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Emc
Version 5.5.1.3
Version 5.5.1
Version 5.5.2.3
Version 5.5
Version 5.5 sp1

References (4)

Source: security_alert@emc.com
Source: security_alert@emc.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.