PT-2002-3120 · Gordano · Gordano Messaging Server (Gms) Mail
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2408
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gordano Messaging Server (GMS) Mail 8
Description
The issue allows remote attackers to bypass JUCE filters by sending an email message to more than one user on the GMS server, as the server only filters email messages for the first recipient.
Recommendations
For Gordano Messaging Server (GMS) Mail 8, consider implementing a workaround to filter email messages for all recipients, not just the first one, until a proper fix is available. As a temporary mitigation measure, restrict the ability to send emails to multiple users simultaneously to minimize the risk of filter bypass.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gordano Messaging Server (Gms) Mail