First published: Fri May 11 2007(Updated: )
usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Groupwise Mobile Server | ||
Nokia Intellisync Mobile Suite | =6.4.31.2 | |
Nokia Intellisync Wireless Email Express | ||
Nokia Intellisync Mobile Suite | =6.6.0.107 | |
Nokia Intellisync Mobile Suite | =6.6.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2591 is classified as a medium severity vulnerability that allows remote attackers to modify user account details and potentially cause denial of service.
To fix CVE-2007-2591, you should update to the latest version of Nokia Intellisync Mobile Suite or related software that addresses this vulnerability.
CVE-2007-2591 affects Nokia Intellisync Mobile Suite versions 6.4.31.2, 6.6.0.107, and 6.6.2.2, as well as associated products such as Nokia Groupwise Mobile Server.
CVE-2007-2591 can be exploited by remote attackers to alter user account settings, leading to unauthorized account modifications and potential service disruption.
Yes, CVE-2007-2591 remains a concern for users of the affected versions of Nokia software that have not been patched or updated.