CVE-2009-1636
published 2009-05-26CVE-2009-1636: Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.43%
94.4th percentile
Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | groupwise | — | — |
| novell | groupwise | — | — |
| novell | groupwise | — | — |
| novell | groupwise | — | — |
| novell | groupwise | — | — |
| novell | groupwise | — | — |
| novell | groupwise | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3554 JBoss EAP Twiddle logs the JMX password
bugzilla·2009-11-20·CVSS 2.1
CVE-2009-3554 [LOW] CVE-2009-3554 JBoss EAP Twiddle logs the JMX password
CVE-2009-3554 JBoss EAP Twiddle logs the JMX password
From https://jira.jboss.org/jira/browse/JBPAPP-2872
Twiddle logs all command line arguments, including the JMX password to twiddle.log. This log is publicly readable and is created in the current directory.
Discussion:
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 4
Via RHSA-2009:1636 https://rhn.redhat.com/errata/RHSA-2009-1636.html
---
This issue has been addressed in following products:
JBEAP 4.2.0 for RHEL 4
Via RHSA-2009:1637 https://rhn.redhat.com/errata/RHSA-2009-1637.html
---
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 5
Via RHSA-2009:1649 https://rhn.redhat.com/errata/RHSA-2009-1649.html
---
This issue has been addressed in following products:
JBEAP 4.2.
Bugzilla
CVE-2009-1380 jbossas JMX-Console cross-site-scripting in filter parameter
bugzilla·2009-07-14·CVSS 4.3
CVE-2009-1380 [MEDIUM] CVE-2009-1380 jbossas JMX-Console cross-site-scripting in filter parameter
CVE-2009-1380 jbossas JMX-Console cross-site-scripting in filter parameter
From JBPAPP-1983 (https://jira.jboss.org/jira/browse/JBPAPP-1983):
The jmx console does not encode quote characters if they trailing after the
colon (key property) , which allows cross-site-scripting attacks.
Discussion:
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 4
Via RHSA-2009:1636 https://rhn.redhat.com/errata/RHSA-2009-1636.html
---
This issue has been addressed in following products:
JBEAP 4.2.0 for RHEL 4
Via RHSA-2009:1637 https://rhn.redhat.com/errata/RHSA-2009-1637.html
---
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 5
Via RHSA-2009:1649 https://rhn.redhat.com/errata/RHSA-2009-1649.html
---
This issue has been addressed in followin
http://osvdb.org/54644http://osvdb.org/54645http://secunia.com/advisories/35177http://www.novell.com/support/viewContent.do?externalId=7003272&sliceId=1http://www.novell.com/support/viewContent.do?externalId=7003273&sliceId=1http://www.securityfocus.com/archive/1/503724/100/0/threadedhttp://www.securityfocus.com/bid/35064http://www.securityfocus.com/bid/35065http://www.securitytracker.com/id?1022276http://www.vupen.com/english/advisories/2009/1393http://www.vupen.com/exploits/Novell_GroupWise_GWIA_Email_Address_Remote_Buffer_Overflow_Exploit_1393141.phphttp://www.vupen.com/exploits/Novell_GroupWise_GWIA_SMTP_Command_Remote_Buffer_Overflow_PoC_Exploit_1393140.phphttps://bugzilla.novell.com/show_bug.cgi?id=478892https://bugzilla.novell.com/show_bug.cgi?id=482914https://exchange.xforce.ibmcloud.com/vulnerabilities/50692https://exchange.xforce.ibmcloud.com/vulnerabilities/50693http://osvdb.org/54644http://osvdb.org/54645http://secunia.com/advisories/35177http://www.novell.com/support/viewContent.do?externalId=7003272&sliceId=1http://www.novell.com/support/viewContent.do?externalId=7003273&sliceId=1http://www.securityfocus.com/archive/1/503724/100/0/threadedhttp://www.securityfocus.com/bid/35064http://www.securityfocus.com/bid/35065http://www.securitytracker.com/id?1022276http://www.vupen.com/english/advisories/2009/1393http://www.vupen.com/exploits/Novell_GroupWise_GWIA_Email_Address_Remote_Buffer_Overflow_Exploit_1393141.phphttp://www.vupen.com/exploits/Novell_GroupWise_GWIA_SMTP_Command_Remote_Buffer_Overflow_PoC_Exploit_1393140.phphttps://bugzilla.novell.com/show_bug.cgi?id=478892https://bugzilla.novell.com/show_bug.cgi?id=482914https://exchange.xforce.ibmcloud.com/vulnerabilities/50692https://exchange.xforce.ibmcloud.com/vulnerabilities/50693
2009-05-26
Published