PT-2004-3230 · Novell+1 · Groupwise Webaccess+2

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2336

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Novell GroupWise and GroupWise WebAccess versions 6.0 through 6.5
Description: The issue allows remote attackers to read directories and files on the server when Novell GroupWise and GroupWise WebAccess are running with Apache Web Server 1.3 for NetWare, where Apache is loaded using GWAPACHE.CONF.
Recommendations: For versions 6.0 through 6.5, consider restricting access to sensitive directories and files on the server as a temporary workaround until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2336

Affected Products

Apache Web Server
Groupwise Webaccess
Novell Groupwise