Skip to main content

Novell GroupWise WebAccess Directory Traversal Vulnerability

Last Update Date: 3 Jul 2012 15:56 Release Date: 3 Jul 2012 4409 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Novell GroupWise WebAccess. A remote user can view files on the target system.

The software does not properly validate user-supplied input in the 'User.interface' parameter. A remote user can supply a specially crafted request to view files on target system under the WebAccess directory structure.


Impact

  • Information Disclosure

System / Technologies affected

  • Novell GroupWise 8.x
  • Novell GroupWise 8 WebAccess

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (8.0 Support Pack 3).

Vulnerability Identifier


Source


Related Link