Vulnerabilities (CVE)

Filtered by vendor Novell Subscribe
Filtered by product Service Desk
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1593 1 Novell 1 Service Desk 2018-10-09 6.5 MEDIUM 7.2 HIGH
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.