PT-2016-1532 · Apple · Os X Server

Shawn Pullum

·

Published

2016-03-24

·

Updated

2016-12-20

·

CVE-2016-1776

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple OS X Server versions prior to 5.1
Description The issue is related to the Web Server component in Apple OS X Server, which does not properly restrict access to .DS Store and .htaccess files. This allows remote attackers to obtain sensitive configuration information via an HTTP request. The vulnerability can be exploited by sending an HTTP request to access these files, potentially revealing confidential configuration details.
Recommendations For Apple OS X Server versions prior to 5.1, update to version 5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the .DS Store and .htaccess files to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00833
CVE-2016-1776

Affected Products

Os X Server