35177Third-party advisory
http://secunia.com/advisories/35177 CVE-2009-1634
Novell Groupwise 8.0 Webaccess - Multiple Vulnerabilities
Record summary
CVE-2009-1634 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNovell Groupwise 8.0 Webaccess - Multiple VulnerabilitiesExploitDB exploitby Gregory DucheminNot analyzed1 file
References
7novell.comConfirmation
http://www.novell.com/support/viewContent.do?externalId=7003266&sliceId=1 35066vdb entry
http://www.securityfocus.com/bid/35066 ADV-2009-1393vdb entry
http://www.vupen.com/english/advisories/2009/1393 bugzilla.novell.com
https://bugzilla.novell.com/show_bug.cgi?id=472979 groupwise-session-unauth-access(50688)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/50688 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-1634