Lucene search

K
cve[email protected]CVE-2009-1634
HistoryMay 26, 2009 - 3:30 p.m.

CVE-2009-1634

2009-05-2615:30:05
web.nvd.nist.gov
23
novell
groupwise
webaccess
session management
vulnerability
cve-2009-1634

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.163 Low

EPSS

Percentile

96.0%

The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.

Affected configurations

NVD
Node
novellgroupwiseMatch7.0
OR
novellgroupwiseMatch7.0.0sp1
OR
novellgroupwiseMatch7.0.0sp2
OR
novellgroupwiseMatch7.0.2
OR
novellgroupwiseMatch7.0.3
OR
novellgroupwiseMatch7.03hp1a
OR
novellgroupwiseMatch7.03hp2
OR
novellgroupwiseMatch8.0
OR
novellgroupwiseMatch8.0hp1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.163 Low

EPSS

Percentile

96.0%

Related for CVE-2009-1634