← Back

CVE-2016-1595

nvd nist
Published: Apr 22, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.

Affected (1)

Products: Novell: Service Desk
1 product
Service Desk
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.1

Timeline

No history available yet.