CVE-2001-1458: Medium severity Novell GroupWise vulnerability
Published Oct 15, 2001
·Updated
Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.
Affected Software
3 affected components
Novell GroupWise=5.5
Novell GroupWise=5.5
Novell GroupWise=6.0
Event History
Oct 15, 2001
CVE Published
04:00 AM
Apr 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1458?
CVE-2001-1458 is considered a medium severity directory traversal vulnerability.
2
How do I fix CVE-2001-1458?
To fix CVE-2001-1458, apply the latest patches or updates from Novell for GroupWise 5.5 and 6.0.
3
What versions of GroupWise are affected by CVE-2001-1458?
CVE-2001-1458 affects Novell GroupWise versions 5.5 and 6.0.
4
What type of attack does CVE-2001-1458 allow?
CVE-2001-1458 allows remote attackers to read arbitrary files on the server using directory traversal techniques.
5
Can I test for CVE-2001-1458 in my environment?
Yes, you can test for CVE-2001-1458 by attempting to access files through the vulnerable URL pattern with directory traversal sequences.