Vulnerabilities
Vulnerable Software
Novell:  >> Groupwise  Security Vulnerabilities
Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.
CVSS Score
7.5
EPSS Score
0.021
Published
2005-08-03
NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue
CVSS Score
5.0
EPSS Score
0.008
Published
2005-01-17
Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.
CVSS Score
5.0
EPSS Score
0.005
Published
2004-12-31
Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."
CVSS Score
10.0
EPSS Score
0.004
Published
2003-12-31
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
CVSS Score
7.5
EPSS Score
0.092
Published
2002-10-04
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
CVSS Score
5.0
EPSS Score
0.002
Published
2002-06-25
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.
CVSS Score
4.6
EPSS Score
0.0
Published
2002-05-31
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
CVSS Score
7.5
EPSS Score
0.047
Published
2001-12-15
Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
CVSS Score
5.0
EPSS Score
0.009
Published
2001-10-15
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
CVSS Score
5.0
EPSS Score
0.017
Published
2001-08-14


Contact Us

Shodan ® - All rights reserved