Vulnerability CVE-2016-0899


Published: 2016-07-04

Description:
EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.

CVSS2 => (AV:N/AC:M/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
EMC -> Rsa archer egrc 

 References:
http://seclists.org/bugtraq/2016/Jun/54
http://www.securitytracker.com/id/1036080

Copyright 2021, cxsecurity.com

 

Back to Top