CVE-2009-1634
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.22% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- novell/groupwise
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35177Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7003266&sliceId=1Vendor Advisory
- http://www.securityfocus.com/bid/35066
- http://www.vupen.com/english/advisories/2009/1393Vendor Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=472979Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50688
- http://secunia.com/advisories/35177Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7003266&sliceId=1Vendor Advisory
- http://www.securityfocus.com/bid/35066
- http://www.vupen.com/english/advisories/2009/1393Vendor Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=472979Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50688
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.