Check Point Reference: | CPAI-2014-1873 |
Date Published: | 22 Oct 2014 |
Severity: | High |
Last Updated: | Wednesday 22 October, 2014 |
Source: | Novell |
Industry Reference: | CVE-2014-0600 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Novell GroupWise 2014 prior to SP1 |
Vulnerability Description | A directory traversal vulnerability exists within the Administration Service of Novell GroupWise 2014. The vulnerability is due to a flaw in handling of a parameter in the FileUploadServlet servlet. A remote unauthenticated attacker can exploit this vulnerability by sending crafted requests to the vulnerable service. Successful exploitation allows an attacker to disclose or destroy arbitrary files on the server. |
SmartView Tracker will log the following entries:
Attack Name: Application Servers Protection Violation.
Attack Information: Novell GroupWise Admin Service FileUploadServlet Directory Traversal