First published: Fri May 03 2002(Updated: )
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus GroupWise | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0303 is classified as a high severity vulnerability due to the ease of exploitation that allows unauthorized access to user accounts.
To fix CVE-2002-0303, ensure that LDAP authentication is configured with a non-blank username and password.
CVE-2002-0303 specifically affects GroupWise version 6.0.
Yes, attackers can exploit CVE-2002-0303 remotely to gain privileges by logging in without a password.
CVE-2002-0303 involves LDAP authentication that is improperly configured.