CVE-2016-0899 Information

Description

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file and obtain sensitive credential information by modifying the IIS configuration to set a Content-Type header for .bak files.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Reference

http://seclists.org/bugtraq/2016/Jun/54 http://www.securitytracker.com/id/1036080

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

6.3

Share on: