CVE-2016-1605

Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.

Date published : 2016-07-31

https://www.netiq.com/support/kb/doc.php?id=7017803

http://www.zerodayinitiative.com/advisories/ZDI-16-406