5

CVE-2005-0296

NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page.  NOTE: the vendor has disputed this issue
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Groupwise Version 6.0
Novell ≫ Groupwise Version 6.0 Update sp1
Novell ≫ Groupwise Version 6.0 Update sp2
Novell ≫ Groupwise Version 6.0 Update sp3
Novell ≫ Groupwise Version 6.0 Update sp4
Novell ≫ Groupwise Version 6.5
Novell ≫ Groupwise Version 6.5 Update sp1
Novell ≫ Groupwise Version 6.5 Update sp2
Novell ≫ Groupwise Webaccess Version 6.0 Update sp4
Novell ≫ Groupwise Webaccess Version 6.5
Novell ≫ Groupwise Webaccess Version 6.5 Update sp1
Novell ≫ Groupwise Webaccess Version 6.5 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.62% 0.835
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=110608203729814&w=2
http://support.novell.com/servlet/tidfinder/10096251
Vendor Advisory
http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html
Vendor Advisory
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html
Vendor Advisory
http://www.osvdb.org/13135
http://www.securityfocus.com/bid/12285
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/18954