First published: Wed Jul 22 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus GroupWise | <=2012 | |
Micro Focus GroupWise | <=2014 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0611 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2014-0611, update Novell GroupWise to version 2012 Support Pack 4 or 2014 Support Pack 2 or later.
CVE-2014-0611 includes multiple cross-site scripting (XSS) vulnerabilities that allow injection of arbitrary web scripts or HTML.
CVE-2014-0611 affects Novell GroupWise versions prior to 2012 Support Pack 4 and 2014 Support Pack 2.
Remote attackers can exploit the vulnerabilities in CVE-2014-0611 to inject malicious scripts through unspecified vectors.