CVE-2016-1594: Novell Service Desk

Medium severity, CVSS 6.5. EPSS: 6.9% chance of exploitation in the next 30 days.

Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.

Affected products

  • Novell Service Desk: up to and including 7.1

Published 2016-04-22. Last modified 2026-06-17.