CVE-2008-1330: Infoleak
Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1330?
CVE-2008-1330 is rated as a medium severity vulnerability.
How do I fix CVE-2008-1330?
To mitigate CVE-2008-1330, users should upgrade to Novell GroupWise 7.0 SP3 or later or to GroupWise 6.5 SP6 Update 3 or later.
Who is affected by CVE-2008-1330?
CVE-2008-1330 affects Novell GroupWise versions 6.5 prior to SP6 and 7.0 prior to SP3.
What type of vulnerability is CVE-2008-1330?
CVE-2008-1330 is an access control vulnerability that allows unauthorized access to non-shared stored emails.
Can remote users exploit CVE-2008-1330?
Yes, remote authenticated users can exploit CVE-2008-1330 to access emails of others who have shared folders.