CVE-2009-1634: High severity Novell GroupWise vulnerability
Published May 26, 2009
·Updated
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.
Affected Software
9 affected components
Novell GroupWise=8.0-hp1
Novell GroupWise=7.0
Novell GroupWise=7.03-hp2
Novell GroupWise=7.0.2
Novell GroupWise=8.0
Novell GroupWise=7.0.0-sp1
Novell GroupWise=7.0.3
Novell GroupWise=7.03-hp1a
Novell GroupWise=7.0.0-sp2
Event History
May 26, 2009
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1634?
CVE-2009-1634 is classified as a medium severity vulnerability.
2
How do I fix CVE-2009-1634?
To fix CVE-2009-1634, upgrade to Novell GroupWise version 7.03 HP3 or 8.0 HP2 or later.
3
What component is affected by CVE-2009-1634?
The WebAccess component of Novell GroupWise is affected by CVE-2009-1634.
4
Can CVE-2009-1634 allow unauthorized access?
Yes, CVE-2009-1634 allows remote attackers to gain access to user accounts due to improper session management.
5
Which versions of Novell GroupWise are vulnerable to CVE-2009-1634?
Versions of Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 are vulnerable to CVE-2009-1634.