CVE-2016-5765
CVSS V2 Medium 4.3
CVSS V3 Medium 6.5
Description
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal. Applies to MSS 12.3 before 12.3.326 and MSS 12.2 before 12.2.342 and RSG 12.1 before 12.1.362 and RWeb 12.3 before 12.3.312 and RWeb 12.2 before 12.2.342 and RWeb 12.1 before 12.1.362 and ZFE 2.0.1 before 2.0.1.18 and ZFE 2.0.0 before 2.0.0.52 and ZFE 1.4.0 before 1.4.0.14.
Overview
- CVE ID
- CVE-2016-5765
- Assigner
- meissner@suse.de
- Vulnerability Status
- Modified
- Published Version
- 2016-11-29T11:59:00
- Last Modified Date
- 2016-12-24T02:59:41
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:microfocus:host_access_management_and_security_server:12.2:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:host_access_management_and_security_server:12.3:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_for_the_web:12.1:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_for_the_web:12.2:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_for_the_web:12.3:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_security_gateway:12.1:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_zfe:1.4.0.14:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_zfe:2.0.0.52:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:microfocus:reflection_zfe:2.0.1.18:*:*:*:*:*:*:* | 1 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:M/Au:N/C:P/I:N/A:N
- Access Vector
- NETWORK
- Access Compatibility
- MEDIUM
- Authentication
- NONE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- NONE
- Availability Impact
- NONE
- Base Score
- 4.3
- Severity
- MEDIUM
- Exploitability Score
- 8.6
- Impact Score
- 2.9
CVSS Version 3
- Version
- 3.0
- Vector String
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Attack Vector
- NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- NONE
- User Interaction
- REQUIRED
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- NONE
- Base Score
- 6.5
- Base Severity
- MEDIUM
- Exploitability Score
- 2.8
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
http://support.attachmate.com/techdocs/1704.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/94579 | |
http://www.zerodayinitiative.com/advisories/ZDI-16-618 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2016-5765 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5765 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 09:54:53 | Added to TrackCVE | |||
2022-12-02 12:12:54 | security@suse.com | meissner@suse.de | CVE Assigner | updated |
2022-12-02 12:12:54 | 2016-11-29T11:59Z | 2016-11-29T11:59:00 | CVE Published Date | updated |
2022-12-02 12:12:54 | 2016-12-24T02:59:41 | CVE Modified Date | updated | |
2022-12-02 12:12:55 | Modified | Vulnerability Status | updated |