CVE-2016-1608: Novell Filr

High severity, CVSS 8.8. EPSS: 11.3% chance of exploitation in the next 30 days.

vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.

Affected products

  • Novell Filr: up to and including 1.2; up to and including 2.0

Published 2016-08-01. Last modified 2026-06-17.