vendor:
GroupWise
by:
Francis Provencher
7.5
CVSS
HIGH
Remote code-execution, Information-disclosure, Cross-site scripting
CWE
Product Name: GroupWise
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Novell GroupWise Multiple Vulnerabilities
The vulnerabilities in Novell GroupWise allow for multiple attacks including remote code-execution, information-disclosure, and cross-site scripting. By exploiting these vulnerabilities, an attacker can steal cookie-based authentication credentials, obtain sensitive information, or execute arbitrary code in the context of the user running the affected application. The harvested information can be used for further attacks, and other attacks are also possible.
Mitigation:
Apply the latest patches and updates from Novell. Implement strong authentication mechanisms and user input validation to mitigate the risk of code execution and information disclosure. Regularly monitor for any suspicious activity.