CVE-2009-0272
Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 - Cross-Site Request Forgery
Title source: llmDescription
Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33744
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/search.do?usemicrosite=true&searchString=7002319
Various Sources x_refsource_misc
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-21
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500569/100/0/threaded
Scores
EPSS
0.0020
EPSS Percentile
42.1%
Details
CWE
CWE-352
Status
published
Products (6)
novell/groupwise
6.5
novell/groupwise
7.0
novell/groupwise
7.01
novell/groupwise
7.02x
novell/groupwise
7.03 (2 CPE variants)
novell/groupwise
8.0
Published
Feb 02, 2009
Tracked Since
Feb 18, 2026