CVE-2009-0272: CSRF
Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0272?
CVE-2009-0272 is categorized as a critical vulnerability due to its potential for remote exploitation that could lead to unauthorized configuration changes.
How do I fix CVE-2009-0272?
To mitigate CVE-2009-0272, upgrade to a patched version of Novell GroupWise that addresses this CSRF vulnerability.
Which versions of Novell GroupWise are affected by CVE-2009-0272?
CVE-2009-0272 affects Novell GroupWise versions 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0.
What type of vulnerability is CVE-2009-0272?
CVE-2009-0272 is classified as a cross-site request forgery (CSRF) vulnerability.
What can attackers achieve through CVE-2009-0272?
Attackers can exploit CVE-2009-0272 to insert e-mail forwarding rules and potentially alter other configuration settings as arbitrary users.