Security Advisory

CVE-2016-0899

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-07-04 16:00:00
Last updated 2024-08-05 22:38:41
Assigner dell
CVSS score not scored
State PUBLISHED

Description

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential information, by modifying the IIS configuration to set a Content-Type header for .bak files.