Lucene search

K
cve[email protected]CVE-2011-2662
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-2662

2022-10-0316:15:15
CWE-189
web.nvd.nist.gov
25
cve-2011-2662
novell groupwise
gwia
groupwise 8.0
remote code execution
vcalendar attachment
integer signedness error

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.632 Medium

EPSS

Percentile

97.9%

Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message.

Affected configurations

NVD
Node
novellgroupwiseMatch8.0
OR
novellgroupwiseMatch8.0hp1
OR
novellgroupwiseMatch8.0hp2
CPENameOperatorVersion
novell:groupwisenovell groupwiseeq8.0

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.632 Medium

EPSS

Percentile

97.9%