First published: Thu Jul 05 2012(Updated: )
Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus GroupWise | <=8.02 | |
Micro Focus GroupWise | =5.2 | |
Micro Focus GroupWise | =5.5 | |
Micro Focus GroupWise | =5.57e | |
Micro Focus GroupWise | =6.0 | |
Micro Focus GroupWise | =6.0.1-sp1 | |
Micro Focus GroupWise | =6.5 | |
Micro Focus GroupWise | =6.5-sp1 | |
Micro Focus GroupWise | =6.5-sp2 | |
Micro Focus GroupWise | =6.5-sp3 | |
Micro Focus GroupWise | =6.5-sp4 | |
Micro Focus GroupWise | =6.5-sp5 | |
Micro Focus GroupWise | =6.5-sp6 | |
Micro Focus GroupWise | =6.5.2 | |
Micro Focus GroupWise | =6.5.3 | |
Micro Focus GroupWise | =6.5.4 | |
Micro Focus GroupWise | =6.5.6 | |
Micro Focus GroupWise | =6.5.7 | |
Micro Focus GroupWise | =7.0 | |
Micro Focus GroupWise | =7.0.3-hp4 | |
Micro Focus GroupWise | =7.0.3-hp5 | |
Micro Focus GroupWise | =7.0.4 | |
Micro Focus GroupWise | =7.0.4-ftf | |
Micro Focus GroupWise | =7.01 | |
Micro Focus GroupWise | =7.01-ir1 | |
Micro Focus GroupWise | =7.02 | |
Micro Focus GroupWise | =7.02-hp1 | |
Micro Focus GroupWise | =7.02-hp1a | |
Micro Focus GroupWise | =7.02-hp2 | |
Micro Focus GroupWise | =7.02-hp2r1 | |
Micro Focus GroupWise | =7.03 | |
Micro Focus GroupWise | =7.03-hp | |
Micro Focus GroupWise | =7.03-hp2 | |
Micro Focus GroupWise | =7.03-hp3 | |
Micro Focus GroupWise | =7.03-hp3\+ftf | |
Micro Focus GroupWise | =8.0 | |
Micro Focus GroupWise | =8.00-hp1 | |
Micro Focus GroupWise | =8.00-hp2 | |
Micro Focus GroupWise | =8.01 | |
Micro Focus GroupWise | =8.01-hp | |
Micro Focus GroupWise | =8.02 | |
Micro Focus GroupWise | =8.02-hp1 | |
Micro Focus GroupWise | =8.02-hp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-0410 is classified as medium due to its potential for unauthorized file access.
To fix CVE-2012-0410, upgrade to Novell GroupWise version 8.03 or later that addresses this vulnerability.
CVE-2012-0410 allows attackers to read arbitrary files from the server, which may include sensitive information.
CVE-2012-0410 affects multiple versions of Novell GroupWise before 8.03, including versions from 5.2 to 8.02.
Organizations using vulnerable versions of Novell GroupWise are at risk from remote attackers exploiting this directory traversal vulnerability.