CVE-2016-1594 describes a vulnerability in Micro Focus Novell Service Desk versions prior to 7.2, allowing remote authenticated users to read arbitrary attachments. This flaw, categorized as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), enables attackers to access sensitive data through specific LiveTime.woa URL requests, such as downloadLogFiles or downloadFile actions. The vulnerability has a CVSSv3 score of 6.5 (Medium), indicating a network-based attack with low attack complexity and requiring low privileges, leading to high confidentiality impact without affecting integrity or availability. Its FAUCET Risk Score is 87/100, suggesting a significant risk despite the medium CVSS score. Currently, there is no evidence of active exploitation, and it is not listed in the KEV catalog. While there is an ExploitDB entry (EDB-39687) mentioning multiple vulnerabilities in Novell ServiceDesk versions, specific exploit code for CVE-2016-1594 is not explicitly detailed. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1CPE matchmatch criteria | cpe:2.3:a:novell:service_desk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.