Description
|
|
Multiple vulnerabilities have been identified in Novell GroupWise, which could be exploited by attackers to gain knowledge of sensitive information or bypass security restrictions.
The first issue is caused by input validation errors in the HTTP interfaces for GroupWise agents (Message Transfer Agent, Post Office Agent, Internet Agent, WebAccess Agent, Monitor Agent), which could allow cross site scripting attacks.
The second vulnerability is caused by input validation errors in the HTTP interfaces for GroupWise agents (Message Transfer Agent, Post Office Agent, Internet Agent, WebAccess Agent, Monitor Agent), which could allow attackers to inject arbitrary headers.
The third issue is caused by input validation errors in the WebAccess component, which could allow cross site scripting attacks.
|