>> Novell GroupWise Windows Client API Security Bypass Vulnerability
Title : Novell GroupWise Windows Client API Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-0904 CVE ID : CVE-2008-1330
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-17
Technical Description
A vulnerability has been identified in Novell GroupWise, which could be exploited by malicious users to bypass security restrictions and disclose sensitive information. This issue is caused by an error in the Windows client API, which could be exploited by an authenticated attacker to gain unauthorized access to non-shared email in the mailbox of a sharer.