CVE-2014-0600

Novell GroupWise - Arbitrary File Read and Write via FileUploadServlet poLibMaintenanceFileSave Parameter

Title source: llm
STIX 2.1

Description

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-296/
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=879192
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7015566
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030801

Scores

EPSS 0.0572
EPSS Percentile 90.5%

Details

CWE
CWE-200
Status published
Products (1)
novell/groupwise 2014
Published Aug 29, 2014
Tracked Since Feb 18, 2026