4
CVSSv2

CVE-2015-7675

Published: 10/02/2016 Updated: 18/02/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The "Send as attachment" feature in Ipswitch MOVEit DMZ prior to 8.2 and MOVEit Mobile prior to 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.

Vulnerable Product Search on Vulmon Subscribe to Product

ipswitch moveit dmz

ipswitch moveit mobile

Exploits

Ipswitch MOVEit DMZ versions 81 and below suffer from an authorization bypass vulnerability ...
Ipswitch MOVEit DMZ versions 81 and below suffer from a file id enumeration vulnerability ...