Security Advisory
CVE-2015-7677
4.3
MEDIUM
Vulnerability Description
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
Published Date
February 10, 2016
Official Source
NIST NVD Advisory