CVE-2016-1605

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/08/2016
Last modified:
12/04/2025

Description

Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netiq:sentinel:7.4:*:*:*:*:*:*:*
cpe:2.3:a:netiq:sentinel:7.4.1:*:*:*:*:*:*:*