CVE Vulnerabilities

CVE-2009-1634

Published: May 26, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
GroupwiseNovell7.0 (including)7.0 (including)
GroupwiseNovell7.0.0-sp1 (including)7.0.0-sp1 (including)
GroupwiseNovell7.0.0-sp2 (including)7.0.0-sp2 (including)
GroupwiseNovell7.0.2 (including)7.0.2 (including)
GroupwiseNovell7.0.3 (including)7.0.3 (including)
GroupwiseNovell7.03-hp1a (including)7.03-hp1a (including)
GroupwiseNovell7.03-hp2 (including)7.03-hp2 (including)
GroupwiseNovell8.0 (including)8.0 (including)
GroupwiseNovell8.0-hp1 (including)8.0-hp1 (including)

References