HTTP: Micro Focus NetIQ Sentinel Server SentinelContext Authentication Bypass

This signature detects attempts to exploit a known vulnerability in the Micro Focus NetIQ Sentinel Server. Successful exploitation allows the attacker to bypass authentication and gain access to the web application as admin user.

Extended Description

Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.

Affected Products

Netiq sentinel

References

CVE: CVE-2016-1605

Short Name
HTTP:MICROFOCUS-NETIQ-AB
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Authentication Bypass CVE-2016-1605 Focus Micro NetIQ Sentinel SentinelContext Server
Release Date
07/26/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Netiq

CVSS Score

6.8

Found a potential security threat?