|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
Groupwise contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plain text passwords through an unspecified man-in-the-middle attack, which may lead to a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality
Solution:
Patch,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, Novell has released a patch to address this vulnerability. Upgrade to groupwise 6.5 SP6 dated May 22, 2007 or newer for the 6.5 line, and 7 SP2 dated May 24, 2007 or newer for the 7 line.
|
|
Products |
|
Groupwise
 |
6.5 GA |
6.5 SP1 |
6.5 SP2 |
6.5 SP3 |
6.5 SP4 |
6.5 SP5 |
6.5 SP6 |
7.0 GA |
7.0 SP1 |
7.0 SP2 |
|
|
|
|
|
|
Credit |
- Andreas Schmidt - cirosec GmbH
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|