CVE-2004-2336
Summary
| CVE | CVE-2004-2336 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Novell | Groupwise | 6.0 | All | All | All |
| Application | Novell | Groupwise | 6.0 | sp1 | All | All |
| Application | Novell | Groupwise | 6.0 | sp2 | All | All |
| Application | Novell | Groupwise | 6.0 | sp3 | All | All |
| Application | Novell | Groupwise | 6.0 | sp4 | All | All |
| Application | Novell | Groupwise | 6.5 | All | All | All |
| Application | Novell | Groupwise | 6.5 | sp1 | All | All |
| Application | Novell | Groupwise | 6.5 | sp2 | All | All |
| Operating System | Novell | Netware | 6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TID-10091330 Potential security issue with GroupWise WebAccess 6.0 and 6.5 ( 08MAR2004) | af854a3a-2127-422b-91ae-364da2661108 | support.novell.com | Patch |
| Secunia - Advisories - Novell Groupwise WebAccess Insecure Default Configuration | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Patch |
| Novell GroupWise WebAccess Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.