CVE-2016-5763
Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update 10989) might allow authenticated remote attackers to perform unauthorized file access and modification.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- novell/open enterprise server 11 · novell/open enterprise server 2015
- Source
- security@opentext.com
References
- http://download.novell.com/Download?buildid=3Ho1yp5JOXA~
- http://download.novell.com/Download?buildid=Fj0Hdns7mxA~
- http://download.novell.com/Download?buildid=dfqmrymc0Rg~
- http://download.novell.com/Download?buildid=s9_RxhgC8KU~
- http://www.securityfocus.com/bid/94348
- http://download.novell.com/Download?buildid=3Ho1yp5JOXA~
- http://download.novell.com/Download?buildid=Fj0Hdns7mxA~
- http://download.novell.com/Download?buildid=dfqmrymc0Rg~
- http://download.novell.com/Download?buildid=s9_RxhgC8KU~
- http://www.securityfocus.com/bid/94348
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.