{"api_version":"1","generated_at":"2026-07-23T10:16:59+00:00","cve":"CVE-2004-2336","urls":{"html":"https://cve.report/CVE-2004-2336","api":"https://cve.report/api/cve/CVE-2004-2336.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2336","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2336"},"summary":{"title":"CVE-2004-2336","description":"Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091330.htm","name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091330.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"TID-10091330 Potential security issue with GroupWise WebAccess 6.0 and 6.5 ( 08MAR2004)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/11119","name":"http://secunia.com/advisories/11119","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Novell Groupwise WebAccess Insecure Default Configuration","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15467","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/alerts/2004/Mar/1009417.html","name":"http://www.securitytracker.com/alerts/2004/Mar/1009417.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"SecurityTracker.com Archives - GroupWise WebAccess With Apache on NetWare Has Configuration Flaw That May Grant Web Access to Remote Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9864","name":"http://www.securityfocus.com/bid/9864","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Novell GroupWise WebAccess Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2336","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2336","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.0","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.0","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.0","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"groupwise","cpe6":"6.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2336","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"novell","cpe5":"netware","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:22:13.683Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091330.htm"},{"name":"1009417","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/alerts/2004/Mar/1009417.html"},{"name":"groupwise-obtain-information(15467)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15467"},{"name":"11119","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/11119"},{"name":"9864","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9864"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-03-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091330.htm"},{"name":"1009417","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/alerts/2004/Mar/1009417.html"},{"name":"groupwise-obtain-information(15467)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15467"},{"name":"11119","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/11119"},{"name":"9864","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9864"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2336","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091330.htm","refsource":"CONFIRM","url":"http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091330.htm"},{"name":"1009417","refsource":"SECTRACK","url":"http://www.securitytracker.com/alerts/2004/Mar/1009417.html"},{"name":"groupwise-obtain-information(15467)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15467"},{"name":"11119","refsource":"SECUNIA","url":"http://secunia.com/advisories/11119"},{"name":"9864","refsource":"BID","url":"http://www.securityfocus.com/bid/9864"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2336","datePublished":"2005-08-16T04:00:00.000Z","dateReserved":"2005-08-16T00:00:00.000Z","dateUpdated":"2024-08-08T01:22:13.683Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.0:*:*:*:*:*:*:*","matchCriteriaId":"194704B6-4820-4398-8906-A1E529ED65AF"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.0:sp1:*:*:*:*:*:*","matchCriteriaId":"5E0DC694-0DEB-41DE-8A0D-9B649FC2F220"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.0:sp2:*:*:*:*:*:*","matchCriteriaId":"174646C1-60F8-4A84-9C0D-785303EBAF6D"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.0:sp3:*:*:*:*:*:*","matchCriteriaId":"5F5DFFF8-7DCF-48E0-B43E-269EA4F3AE75"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.0:sp4:*:*:*:*:*:*","matchCriteriaId":"A2F5DF0E-8158-4D2E-88CC-BBD7A031054E"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.5:*:*:*:*:*:*:*","matchCriteriaId":"2AD18143-9962-4C0D-AD3D-66C0CF3FB5D0"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.5:sp1:*:*:*:*:*:*","matchCriteriaId":"08A78BE7-6426-41CD-BBAF-9BB951726D33"},{"vulnerable":false,"criteria":"cpe:2.3:a:novell:groupwise:6.5:sp2:*:*:*:*:*:*","matchCriteriaId":"E50599E1-45E5-443F-AAEC-F91778CA4792"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:novell:netware:6.0:*:*:*:*:*:*:*","matchCriteriaId":"EE9F2EF1-D7CB-4D76-BAC0-EA28E5F9D82E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2336","Ordinal":"1","Title":"CVE-2004-2336","CVE":"CVE-2004-2336","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2336","Ordinal":"1","NoteData":"Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.","Type":"Description","Title":"CVE-2004-2336"},{"CveYear":"2004","CveId":"2336","Ordinal":"2","NoteData":"2005-08-16","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2336","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}