Sentinel Server Authentication Bypass and Arbitrary File Download (CVE-2016-1605)

  • 7017803
  • 02-Jul-2016
  • 07-Jul-2016

Environment

NetIQ Sentinel 7.4.x Sentinel Server

Situation

A vulnerability was discovered in NetIQ Sentinel Server that may allow remote attackers to disclose arbitrary file contents. Authentication is required to exploit this vulnerability but it can be bypassed by exploiting a separate flaw in the authentication handling.

Resolution

Customers should upgrade to Sentinel Server 7.4.2 to resolve this vulnerability.

Credit:
This vulnerability was discovered by rgod working with Trend Micro's Zero Day Initiative.

References:
ZDI-16-406

http://www.zerodayinitiative.com/advisories/ZDI-16-406/CVE-2016-1605

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2016-1605