PT-2002-1407 · Novell · Groupwise Webaccess

Published

2002-05-03

·

Updated

2016-10-18

·

CVE-2002-0341

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GroupWise Web Access versions 5.5
Description The issue allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
Recommendations For version 5.5, consider restricting access to the GWWEB.EXE until a patch is available. Avoid using the HTMLVER parameter in the affected HTTP request until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0341

Affected Products

Groupwise Webaccess