CVE-2012-0410: Path Traversal
Published Jul 5, 2012
·Updated
Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.
Affected Software
43 affected components
Novell GroupWise<=8.02
Novell GroupWise=5.2
Novell GroupWise=5.5
Novell GroupWise=5.57e
Novell GroupWise=6.0
Novell GroupWise=6.0.1-sp1
Novell GroupWise=6.5
Novell GroupWise=6.5-sp1
Novell GroupWise=6.5-sp2
Novell GroupWise=6.5-sp3
Novell GroupWise=6.5-sp4
Novell GroupWise=6.5-sp5
Novell GroupWise=6.5-sp6
Novell GroupWise=6.5.2
Novell GroupWise=6.5.3
Novell GroupWise=6.5.4
Novell GroupWise=6.5.6
Novell GroupWise=6.5.7
Novell GroupWise=7.0
Novell GroupWise=7.0.3-hp4
Novell GroupWise=7.0.3-hp5
Novell GroupWise=7.0.4
Novell GroupWise=7.0.4-ftf
Novell GroupWise=7.01
Novell GroupWise=7.01-ir1
Novell GroupWise=7.02
Novell GroupWise=7.02-hp1
Novell GroupWise=7.02-hp1a
Novell GroupWise=7.02-hp2
Novell GroupWise=7.02-hp2r1
Novell GroupWise=7.03
Novell GroupWise=7.03-hp
Novell GroupWise=7.03-hp2
Novell GroupWise=7.03-hp3
Novell GroupWise=7.03-hp3\+ftf
Novell GroupWise=8.0
Novell GroupWise=8.00-hp1
Novell GroupWise=8.00-hp2
Novell GroupWise=8.01
Novell GroupWise=8.01-hp
Novell GroupWise=8.02
Novell GroupWise=8.02-hp1
Novell GroupWise=8.02-hp2
Event History
Jul 5, 2012
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0410?
The severity of CVE-2012-0410 is classified as medium due to its potential for unauthorized file access.
2
How do I fix CVE-2012-0410?
To fix CVE-2012-0410, upgrade to Novell GroupWise version 8.03 or later that addresses this vulnerability.
3
What types of files can be read due to CVE-2012-0410?
CVE-2012-0410 allows attackers to read arbitrary files from the server, which may include sensitive information.
4
Which versions of Novell GroupWise are affected by CVE-2012-0410?
CVE-2012-0410 affects multiple versions of Novell GroupWise before 8.03, including versions from 5.2 to 8.02.
5
Who is at risk from CVE-2012-0410?
Organizations using vulnerable versions of Novell GroupWise are at risk from remote attackers exploiting this directory traversal vulnerability.