CVE-2014-0600
Severity
7.8HIGH
EPSS
5.7%
top 9.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 17
Description
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
CVSS vector
AV:N/AC:L/C:C/I:N/A:NExploitability: 10.0 | Impact: 6.9
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-rqxj-xh63-rpm6: FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via th↗2022-05-17
CVEList▶
CVE-2014-0600: FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via th↗2014-08-29