CVE Feed

    Dashboard / CVE / CVE-2016-5765

    CVE-2016-5765

    Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal. Applies to MSS 12.3 before 12.3.326 and MSS 12.2 before 12.2.342 and RSG 12.1 before 12.1.362 and RWeb 12.3 before 12.3.312 and RWeb 12.2 before 12.2.342 and RWeb 12.1 before 12.1.362 and ZFE 2.0.1 before 2.0.1.18 and ZFE 2.0.0 before 2.0.0.52 and ZFE 1.4.0 before 1.4.0.14.

    Published:Nov 29, 2016
    Last Modified:Apr 12, 2025
    EPS:Nov 29, 2016
    EPSS Score:0.00851
    CVSS Score:6.5

    Affected Products

    Vendor
    Microfocus
    Product
    Host Access Management And Security Server
    Vendor
    Microfocus
    Product
    Reflection For The Web
    Vendor
    Microfocus
    Product
    Reflection Security Gateway
    Vendor
    Microfocus
    Product
    Reflection Zfe

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High