GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/204672 | patch vendor advisory mailing list |
http://www.securityfocus.com/bid/3189 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6998 | vdb entry |
http://support.novell.com/padlock/details.htm | patch vendor advisory |