Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2008/0904 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41223 | vdb entry |
http://securitytracker.com/id?1019616 | vdb entry |
http://secunia.com/advisories/29409 | third party advisory vendor advisory |
https://secure-support.novell.com/KanisaPlatform/Publishing/732/3263374_f.SAL_Public.html | patch |
http://www.securityfocus.com/bid/28265 | vdb entry |