Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:NOVELL:WEBACC-MODIFY

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Novell GroupWise WebAccess Cross Site Scripting Attempt

Release Date

2009/06/09

Update Number

1449

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Novell GroupWise WebAccess Cross Site Scripting Attempt


This signature detects attempts to exploit a known vulnerability against GroupWise WebAccess. Attackers can bypass security restrictions to conduct a cross-site scripting attack.

Extended Description

Novell GroupWise WebAccess is prone to multiple security vulnerabilities. An attacker may leverage these issues to bypass certain security restrictions or conduct cross-site scripting attacks. Note that some of the issues may be related to BID 35061. We will update this BID as more information emerges. Versions prior to WebAccess 7.03 HP3 and 8.0.0 HP2 are vulnerable.

Affected Products

  • Novell Groupwise 7.0.0
  • Novell Groupwise 7.0.0 SP1
  • Novell Groupwise 7.0.0 SP2
  • Novell Groupwise 7.0.0 SP3
  • Novell Groupwise 7.01
  • Novell Groupwise 7.02X
  • Novell Groupwise 7.03
  • Novell Groupwise 7.03Hp1a
  • Novell Groupwise 7.03 HP2
  • Novell Groupwise 8.0
  • Novell Groupwise 8.0 HP1

References

  • BugTraq: 35066
  • CVE: CVE-2009-1635
  • URL: http://www.novell.com/support/viewContent.do?externalId=7003267&sliceId=1

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out