|
|
Info |
Last Modified |
| 4 months ago |
|
|
|
|
Description |
Novell Webaccess contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when apache is loaded using the default gwapache.conf configuration, which will disclose directories and file information resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required,
Local / Remote
Attack Type:
Information Disclosure
Impact:
Loss of Integrity
Solution:
Patch
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
|
|
Solution |
Novell, Inc has released patch FWA652E.EXE to address this issue. Additionally, it is possible correct the flaw by implementing the following workaround:
Add these two lines to the GWAPACHE.CONF under where the DocumentRoot is specified.
Order deny,allow
deny from all
|
|
Products |
|
Apache
 |
1.3x |
Netware
 |
6 |
6.0 |
GroupWise WebAccess
 |
6.5 |
6.0 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|