Lucene search

K
cve[email protected]CVE-2005-0296
HistoryFeb 10, 2005 - 5:00 a.m.

CVE-2005-0296

2005-02-1005:00:00
web.nvd.nist.gov
24
novell
groupwise
webaccess
unauthenticated remote attackers
sensitive information
incorrect login

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the “about” information page. NOTE: the vendor has disputed this issue

Affected configurations

NVD
Node
novellgroupwiseMatch6.0
OR
novellgroupwiseMatch6.0sp1
OR
novellgroupwiseMatch6.0sp2
OR
novellgroupwiseMatch6.0sp3
OR
novellgroupwiseMatch6.0sp4
OR
novellgroupwiseMatch6.5
OR
novellgroupwiseMatch6.5sp1
OR
novellgroupwiseMatch6.5sp2
OR
novellgroupwise_webaccessMatch6.0sp4
OR
novellgroupwise_webaccessMatch6.5
OR
novellgroupwise_webaccessMatch6.5sp1
OR
novellgroupwise_webaccessMatch6.5sp2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.1%

Related for CVE-2005-0296