FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
References
Configurations
History
No history.
Information
Published : 2014-08-29 09:55
Updated : 2024-02-04 18:35
NVD link : CVE-2014-0600
Mitre link : CVE-2014-0600
CVE.ORG link : CVE-2014-0600
JSON object : View
Products Affected
novell
- groupwise
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor