CVE Database · CVE-2016-1595
CVSS v3.1
N/A
EPSS
6.61%
Published
Apr 22, 2016
Modified
May 6, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
Weaknesses (CWE)
Affected Products (1)
References (10)