First published: Wed Mar 03 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell GroupWise | =7.0 | |
Novell GroupWise | =8.0 | |
Novell GroupWise | =7.0-sp1 | |
Novell GroupWise | =7.0-sp3 | |
Novell GroupWise | =7.01 | |
Novell GroupWise | =7.03 | |
Novell GroupWise | =7.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4662 is categorized as a high severity vulnerability due to its potential for exploitation through cross-site scripting.
To remediate CVE-2009-4662, users should upgrade to Novell GroupWise 7.03 HP4 or 8.0 SP1 or later versions.
CVE-2009-4662 affects Novell GroupWise versions 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1.
CVE-2009-4662 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
Organizations using vulnerable versions of Novell GroupWise are primarily affected by CVE-2009-4662.