Novell Sentinel "filename" Arbitrary File Download

by Carol~ Moderator - 4/11/12 4:44 PM

In Reply to: VULNERABILITIES / FIXES - April 11, 2012 by Carol~ Moderator

Novell Sentinel "filename" Arbitrary File Download Vulnerability

Release Date : 2012-04-11

Criticality level : Less critical
Impact : Exposure of sensitive information
Where : From remote
Solution Status : Vendor Patch

Software: Novell Sentinel 7.x

Description:
Novell has acknowledged a vulnerability in Novell Sentinel, which can be exploited by malicious users to disclose sensitive information.

Solution:
Update to version 7.0.1.0 (7.0 SP1).

Original Advisory:
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5138757.html

http://secunia.com/advisories/48760/