Novell GroupWise HTTP Interfaces Directory Traversal Vulnerability
BID:55648
Info
Novell GroupWise HTTP Interfaces Directory Traversal Vulnerability
| Bugtraq ID: | 55648 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0419 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2012 12:00AM |
| Updated: | Sep 11 2012 12:00AM |
| Credit: | Vulnerability Research Team of Digital Defense, Inc. |
| Vulnerable: |
Novell GroupWise 8.0 Support Pack 2 0 Novell Groupwise 2012 0 Novell Groupwise 8.0x Novell Groupwise 8.02 HP3 Novell Groupwise 8.02 HP2 Novell Groupwise 8.02 HP1 Novell Groupwise 8.02 Novell Groupwise 8.01x Novell Groupwise 8.0 SP2 Novell Groupwise 8.0 SP1 Novell Groupwise 8.0 HP3 Novell Groupwise 8.0 HP2 Novell Groupwise 8.0 HP1 Novell Groupwise 8.0 |
| Not Vulnerable: |
Novell GroupWise 8.0 Support Pack 3 0 Novell GroupWise 2012 Support Pack 1 0 |
Discussion
Novell GroupWise HTTP Interfaces Directory Traversal Vulnerability
Novell GroupWise is prone to a directory-traversal vulnerability.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Novell GroupWise is prone to a directory-traversal vulnerability.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Exploit / POC
Novell GroupWise HTTP Interfaces Directory Traversal Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Novell GroupWise HTTP Interfaces Directory Traversal Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Novell GroupWise HTTP Interfaces Directory Traversal Vulnerability
References:
References: