CVE-2016-5763

CRITICAL

Novell Open Enterprise Server - Unauthorized File Access

Title source: llm
STIX 2.1

Description

Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update 10989) might allow authenticated remote attackers to perform unauthorized file access and modification.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94348
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=dfqmrymc0Rg~
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=s9_RxhgC8KU~
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=3Ho1yp5JOXA~
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=Fj0Hdns7mxA~

Scores

CVSS v3 9.1
EPSS 0.0103
EPSS Percentile 77.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-254
Status published
Products (3)
n/a/Novell Open Enterprise Server 11 and 2015 Novell Open Enterprise Server 11 and 2015
novell/open_enterprise_server_11 (2 CPE variants)
novell/open_enterprise_server_2015 (2 CPE variants)
Published Nov 15, 2016
Tracked Since Feb 18, 2026