Novell GroupWise WebAccess Directory Traversal Vulnerability
Last Update Date:
3 Jul 2012 15:56
Release Date:
3 Jul 2012
5377
Views
RISK: Medium Risk
TYPE: Servers - Other Servers

A vulnerability has been identified in Novell GroupWise WebAccess. A remote user can view files on the target system.
The software does not properly validate user-supplied input in the 'User.interface' parameter. A remote user can supply a specially crafted request to view files on target system under the WebAccess directory structure.
Impact
- Information Disclosure
System / Technologies affected
- Novell GroupWise 8.x
- Novell GroupWise 8 WebAccess
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (8.0 Support Pack 3).
Vulnerability Identifier
Source
Related Link
Share with