Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-1330


Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker.


Published

2008-03-18T17:44:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.5 (LOW)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200
    CWE-264
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5 Yes
Application novell groupwise 6.5.2 Yes
Application novell groupwise 6.5.3 Yes
Application novell groupwise 6.5.4 Yes
Application novell groupwise 6.5.6 Yes
Application novell groupwise 6.5.7 Yes
Application novell groupwise 6.5_sp6_update_1 Yes
Application novell groupwise 7.0 Yes
Application novell groupwise 7.0.0 Yes
Application novell groupwise 7.0.0 Yes

References