Vulnerability Details CVE-2022-38756
A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 53.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2022-38756
-
cpe:2.3:a:microfocus:groupwise:18
-
cpe:2.3:a:microfocus:groupwise:18.0.1
-
cpe:2.3:a:microfocus:groupwise:18.0.2
-
cpe:2.3:a:microfocus:groupwise:18.1
-
cpe:2.3:a:microfocus:groupwise:18.1.1
-
cpe:2.3:a:microfocus:groupwise:18.2
-
cpe:2.3:a:microfocus:groupwise:18.2.1
-
cpe:2.3:a:microfocus:groupwise:18.3
-
cpe:2.3:a:microfocus:groupwise:18.3.1
-
cpe:2.3:a:microfocus:groupwise:18.3.2
-
cpe:2.3:a:microfocus:groupwise:18.4
-
cpe:2.3:a:microfocus:groupwise:18.4.1