J-Security Center

Title: Novell GroupWise Network Directory Browsing Vulnerability

Severity: MODERATE

Description:

Novell GroupWise is a messaging system used across intranet and internet environments. GroupWise has various feature including scheduling, calendaring, email, document managemnt etc.

Due to a flaw within GroupWise, it is possible for a user to gain unauthorized access to all existing shares on a network.

When a user creates a new message in GroupWise and attempts to attach a file, a window appears (similar to Windows Explorer) for the user to select a path to the desired file. Unfortunately GroupWise does not verify system policies and enables access to all shares located on the network.

With NT policies and Zen policies implemented properly this vulnerability still exists.

Successful exploitation of this vulnerability could assist in further attacks and possibly lead to complete compromise of the host.

Affected Products:

  • Novell Groupwise 5.5.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.