PT-2001-2549 · Novell · Novell Groupwise
Published
2001-10-15
·
Updated
2017-07-11
·
CVE-2001-1458
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novell GroupWise versions 5.5 through 6.0
Description
A directory traversal issue allows remote attackers to read arbitrary files by making a request for "/servlet/webacc?User.html=" that includes "../" (dot dot) sequences and a null character.
Recommendations
For Novell GroupWise versions 5.5 through 6.0, consider restricting access to the "/servlet/webacc" endpoint until a fix is available. As a temporary workaround, avoid using the
User.html parameter in the affected API endpoint.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Groupwise