CVE-2016-5762
Micro Focus GroupWise Cross Site Scripting / Overflows
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.
Desbordamiento de entero en la función Post Office Agent en Novell GroupWise en versiones anteriores a 2014 R2 Service Pack 1 Hot Patch 1 podría permitir a atacantes remotos ejecutar código arbitrario a través de (1) un nombre de usuario largo o (2) una contraseña larga, lo que desencadena un desbordamiento de bufer basado en memoria dinámica
Micro Focus GroupWise version 2014 R2 SP1 and below suffer from buffer overflow, cross site scripting, and integer overflow vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-06-23 CVE Reserved
- 2016-08-25 CVE Published
- 2024-06-12 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/138503/Micro-Focus-GroupWise-Cross-Site-Scripting-Overflows.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2016/Aug/123 | Mailing List | |
http://www.securityfocus.com/archive/1/539296/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/92642 | Vdb Entry | |
https://www.novell.com/support/kb/doc.php?id=7017975 | X_refsource_confirm | |
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20160825-0_Micro_Focus_GroupWise_Multiple_vulnerabilities_v10.txt | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Groupwise Search vendor "Novell" for product "Groupwise" | <= 2012 Search vendor "Novell" for product "Groupwise" and version " <= 2012" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Groupwise Search vendor "Novell" for product "Groupwise" | 2014 Search vendor "Novell" for product "Groupwise" and version "2014" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Groupwise Search vendor "Novell" for product "Groupwise" | 2014 Search vendor "Novell" for product "Groupwise" and version "2014" | r2 |
Affected
| ||||||
Novell Search vendor "Novell" | Groupwise Search vendor "Novell" for product "Groupwise" | 2014 Search vendor "Novell" for product "Groupwise" and version "2014" | sp1 |
Affected
| ||||||
Novell Search vendor "Novell" | Groupwise Search vendor "Novell" for product "Groupwise" | 2014 Search vendor "Novell" for product "Groupwise" and version "2014" | sp2 |
Affected
|