peter bassill · operator
$ cve CVE-2009-1634 JSON

CVE-2009-1634 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.22% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2009-05-26
Last modified2026-06-16

Affected (1)

VendorProduct
novellgroupwise

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD