The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.
2009-05-26T15:30:05.327
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | novell | groupwise | 7.0 | Yes |
| Application | novell | groupwise | 7.0.0 | Yes |
| Application | novell | groupwise | 7.0.0 | Yes |
| Application | novell | groupwise | 7.0.2 | Yes |
| Application | novell | groupwise | 7.0.3 | Yes |
| Application | novell | groupwise | 7.03 | Yes |
| Application | novell | groupwise | 7.03 | Yes |
| Application | novell | groupwise | 8.0 | Yes |
| Application | novell | groupwise | 8.0 | Yes |