VulnerabilityModified
CVE-2001-1231
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
MEDIUM 5.0EPSS 1.85%
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- novell/groupwise
- Source
- cve@mitre.org
References
- http://support.novell.com/padlock/details.htmPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/204672Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3189
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6998
- http://support.novell.com/padlock/details.htmPatch, Vendor Advisory
- http://www.securityfocus.com/archive/1/204672Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3189
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6998
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.