Novell Groupwise vulnerabilities
74 known vulnerabilities affecting novell/groupwise.
Total CVEs
74
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL24HIGH6MEDIUM43LOW1
Vulnerabilities
Page 4 of 4
CVE-2012-0272P4MEDIUMCVSS 4.3v8.0v8.002012-09-19
CVE-2012-0272 [MEDIUM] CWE-79 CVE-2012-0272: Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before S
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.
nvd
CVE-2002-0303P4MEDIUMCVSS 4.6v6.02002-05-31
CVE-2002-0303 [MEDIUM] CVE-2002-0303: GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password,
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.
nvd
CVE-2005-0296P4MEDIUMCVSS 5.0v6.0v6.52005-01-17
CVE-2005-0296 [MEDIUM] CVE-2005-0296: NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess al
NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor
nvd
CVE-2002-0341P4MEDIUMCVSS 5.0v5.52002-06-25
CVE-2002-0341 [MEDIUM] CVE-2002-0341: GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to deter
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
nvd
CVE-2009-1635P4MEDIUMCVSS 4.3v7.0v7.0.0+6 more2009-05-22
CVE-2009-1635 [MEDIUM] CWE-79 CVE-2009-1635: Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7
Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors assoc
nvd
CVE-2013-1087P4MEDIUMCVSS 4.3≤ 8.03v6.5+17 more2013-07-15
CVE-2013-1087 [MEDIUM] CWE-79 CVE-2013-1087: Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 20
Cross-site scripting (XSS) vulnerability in the client in Novell GroupWise through 8.0.3 HP3, and 2012 through SP2, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML via the body of an e-mail message.
nvd
CVE-2009-4662P4MEDIUMCVSS 4.3v7.0v7.01+2 more2010-03-03
CVE-2009-4662 [MEDIUM] CWE-79 CVE-2009-4662: Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter.
nvd
CVE-2013-1086P4MEDIUMCVSS 4.3v2012≤ 8.03+22 more2013-04-19
CVE-2013-1086 [MEDIUM] CWE-79 CVE-2013-1086: Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.
nvd
CVE-2011-2661P4MEDIUMCVSS 4.3v8.02011-10-08
CVE-2011-2661 [MEDIUM] CWE-79 CVE-2011-2661: Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.
nvd
CVE-2009-1762P4MEDIUMCVSS 4.3v7.0v7.0.0+5 more2009-05-22
CVE-2009-1762 [MEDIUM] CWE-79 CVE-2009-1762: Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in N
Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.
nvd
CVE-2008-3501P4MEDIUMCVSS 4.3v7.0v7.0.2+1 more2008-08-06
CVE-2008-3501 [MEDIUM] CWE-79 CVE-2008-3501: Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x
Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-1999-1006P4MEDIUMCVSS 5.0v5.2v5.51999-12-19
CVE-1999-1006 [MEDIUM] CVE-1999-1006: Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server
Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.
nvd
CVE-2007-3571P4MEDIUMCVSS 4.3v6.0v6.0.1+5 more2007-07-05
CVE-2007-3571 [MEDIUM] CVE-2007-3571: The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain
The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP address.
nvd
CVE-2008-1330P4LOWCVSS 3.5v6.5v6.5.2+7 more2008-03-18
CVE-2008-1330 [LOW] CWE-200 CVE-2008-1330: Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker.
nvd
← Previous4 / 4