Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-5765


Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal. Applies to MSS 12.3 before 12.3.326 and MSS 12.2 before 12.2.342 and RSG 12.1 before 12.1.362 and RWeb 12.3 before 12.3.312 and RWeb 12.2 before 12.2.342 and RWeb 12.1 before 12.1.362 and ZFE 2.0.1 before 2.0.1.18 and ZFE 2.0.0 before 2.0.0.52 and ZFE 1.4.0 before 1.4.0.14.


Published

2016-11-29T11:59:00.177

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-22
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus host_access_management_and_security_server 12.2 Yes
Application microfocus host_access_management_and_security_server 12.3 Yes
Application microfocus reflection_for_the_web 12.1 Yes
Application microfocus reflection_for_the_web 12.2 Yes
Application microfocus reflection_for_the_web 12.3 Yes
Application microfocus reflection_security_gateway 12.1 Yes
Application microfocus reflection_zfe 1.4.0.14 Yes
Application microfocus reflection_zfe 2.0.0.52 Yes
Application microfocus reflection_zfe 2.0.1.18 Yes

References