Skip to main content

Vendor/product archive

novell / service_desk CVEs

Beta · best-effort

4 CVEs tagged to novell / service_desk0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2016-1596

Published Apr 22, 2016

Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a cer…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1595

Published Apr 22, 2016

LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1594

Published Apr 22, 2016

Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1593

Published Apr 22, 2016

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1