Novell GroupWise HTTP POST/GET Request Information Disclosure Vulnerability
BID:33559
Info
Novell GroupWise HTTP POST/GET Request Information Disclosure Vulnerability
| Bugtraq ID: | 33559 |
| Class: | Design Error |
| CVE: |
CVE-2009-0274 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2009 12:00AM |
| Updated: | Feb 02 2009 08:39PM |
| Credit: | Adrian Pastor of ProCheckUp |
| Vulnerable: |
Novell Groupwise 7.0 Novell Groupwise 6.5 Novell Groupwise 8.0 Novell Groupwise 7.03HP1a Novell Groupwise 7.03 Novell Groupwise 7.02x Novell Groupwise 7.01 |
| Not Vulnerable: |
Novell Groupwise 8.0 HP1 Novell Groupwise 7.03 HP2 |
Discussion
Novell GroupWise HTTP POST/GET Request Information Disclosure Vulnerability
Novell GroupWise is prone to an information-disclosure vulnerability when handling HTTP POST requests.
An attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
Novell GroupWise is prone to an information-disclosure vulnerability when handling HTTP POST requests.
An attacker can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
Novell GroupWise HTTP POST/GET Request Information Disclosure Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Novell GroupWise HTTP POST/GET Request Information Disclosure Vulnerability
Solution:
The vendor has released an advisory along with fixes. Please see the references for more information.
Solution:
The vendor has released an advisory along with fixes. Please see the references for more information.
References
Novell GroupWise HTTP POST/GET Request Information Disclosure Vulnerability
References:
References: