vendor:
Groupwise Internet Agent
by:
Francis Provencher
9,3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Groupwise Internet Agent
Affected Version From: GroupWise 7.0, 7.01, 7.02, 7.03x, 7.04, 8.0, 8.01x
Affected Version To: GroupWise 7.0, 7.01, 7.02, 7.03x, 7.04, 8.0, 8.01x
Patch Exists: YES
Related CWE: N/A
CPE: a:novell:groupwise_internet_agent
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Netware
2010
Novell Groupwise Internet Agent Stack Overflow
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installatons of Novell Groupwise Internet Agent. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the HTTP POST request. By sending a specially crafted request, an attacker can cause a stack-based buffer overflow. An attacker can leverage this vulnerability to execute arbitrary code under the context of the user running the application.
Mitigation:
Upgrade to the latest version of Novell Groupwise Internet Agent.