VulnerabilityModified
CVE-2011-2221
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.
MEDIUM 5.0EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- novell/data synchronizer · novell/mobility pack
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/45527Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7009053Vendor Advisory
- http://www.securityfocus.com/bid/49069
- http://secunia.com/advisories/45527Vendor Advisory
- http://www.novell.com/support/viewContent.do?externalId=7009053Vendor Advisory
- http://www.securityfocus.com/bid/49069
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.