CVE-2018-12468: Arbitrary File Upload in GroupWise Administration Console
A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. In certain circumstances this could result in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12468?
CVE-2018-12468 is a vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 that allows a remote attacker to upload files to an arbitrary path on the server.
How can a remote attacker exploit CVE-2018-12468?
A remote attacker can exploit CVE-2018-12468 by authenticating as an administrator and uploading files to an arbitrary path on the server, which may result in remote code execution.
What is the severity of CVE-2018-12468?
CVE-2018-12468 has a severity rating of critical with a CVSS score of 7.2.
Which version of Micro Focus GroupWise is affected by CVE-2018-12468?
Micro Focus GroupWise prior to version 18.0.2 is affected by CVE-2018-12468.
How can I fix CVE-2018-12468?
To fix CVE-2018-12468, you should update Micro Focus GroupWise to version 18.0.2 or later.