Micro.Focus.GroupWise.Post.Office.Agent.Integer.Overflow
Description
This indicates an attack attempt against a Heap overflow vulnerability in Micro Focus GroupWise.
The vulnerability is caused by insufficient validation of usernames and passwords submitted to the Post Office Agent. A remote attacker can exploit this vulnerability by sending a crafted HTTP request to a targeted server and execute arbitrary code in the security context of the root user.
Affected Products
Micro Focus GroupWise 2014
Micro Focus GroupWise 2014 R2 SP1 and prior
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Upgrade to the latest version.
https://www.novell.com/support/kb/doc.php?id=7017975
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-06-09 | 15.861 | Sig Added |
2019-06-10 | 14.629 | Severity:high:critical |