CVE-2005-0296
The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns…
Does this matter?
Lower severity and a low EPSS score (2.62%). Track it; it rarely justifies an emergency change on its own.
Description
NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.62% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- novell/groupwise · novell/groupwise webaccess
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110608203729814&w=2
- http://support.novell.com/servlet/tidfinder/10096251Vendor Advisory
- http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.htmlVendor Advisory
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.htmlVendor Advisory
- http://www.osvdb.org/13135
- http://www.securityfocus.com/bid/12285Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18954
- http://marc.info/?l=bugtraq&m=110608203729814&w=2
- http://support.novell.com/servlet/tidfinder/10096251Vendor Advisory
- http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.htmlVendor Advisory
- http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.htmlVendor Advisory
- http://www.osvdb.org/13135
- http://www.securityfocus.com/bid/12285Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18954
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.