GroupWise WebAccess 6.5 and 7 Multiple Vulnerabilities

Roel van Bueren's picture
Submitted by Roel van Bueren on August 14, 2006 - 9:10am.

Some vulnerabilities have been reported in GroupWise WebAccess 6.5 and 7.0, which can be exploited by malicious people to conduct cross-site scripting and script insertion attacks. These vulnerabilities have been fixed by Novell in GroupWise 7 SP1 WebAccess Hot Patch 1 for NetWare and Windows and the FTF of GroupWise 6.5 Post SP6 WebAccess Rev D.

Please read the 'NOTICE' in these TIDs carefully: If running this Hot Patch on the same server as any other GroupWise components (MTA, POA, GWIA, WebAccess), you will need to update ALL GroupWise agents to either Hot Patch SP1 (GroupWise 7) or GroupWise 6.5 post SP6 Agents Revision 4 to avoid incompatibilities with the newer GroupWise Engine installed with this version.

Categories: