CVE-2016-1593: Novell Service Desk
High severity, CVSS 7.2. EPSS: 64.1% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.
Affected products
- Novell Service Desk: up to and including 7.1
Published 2016-04-22. Last modified 2026-06-17.