CVE-2016-5763
CRITICALNovell Open Enterprise Server - Unauthorized File Access
Title source: llmDescription
Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update 10989) might allow authenticated remote attackers to perform unauthorized file access and modification.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/94348
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=dfqmrymc0Rg~
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=s9_RxhgC8KU~
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=3Ho1yp5JOXA~
Various Sources x_refsource_confirm
http://download.novell.com/Download?buildid=Fj0Hdns7mxA~
Scores
CVSS v3
9.1
EPSS
0.0103
EPSS Percentile
77.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-254
Status
published
Products (3)
n/a/Novell Open Enterprise Server 11 and 2015
Novell Open Enterprise Server 11 and 2015
novell/open_enterprise_server_11
(2 CPE variants)
novell/open_enterprise_server_2015
(2 CPE variants)
Published
Nov 15, 2016
Tracked Since
Feb 18, 2026