CVE-2012-0419

Novell GroupWise <8.0 SP3, <2012 SP1 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in the agent HTTP interfaces in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 allows remote attackers to read arbitrary files via directory traversal sequences in a request.

Exploits (1)

metasploit WORKING POC
by r () b13$, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/groupwise_agents_http_traversal.rb

Scores

EPSS 0.7881
EPSS Percentile 99.1%

Details

CWE
CWE-22
Status published
Products (5)
novell/groupwise 8.0
novell/groupwise 8.00 hp1 (3 CPE variants)
novell/groupwise 8.01 (2 CPE variants)
novell/groupwise 8.02 (4 CPE variants)
novell/groupwise 2012
Published Sep 28, 2012
Tracked Since Feb 18, 2026