Description
A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks.
Published: 2017-03-23
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-9986 A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks.
History

No history.

Subscriptions

Novell Groupwise
cve-icon MITRE

Status: PUBLISHED

Assigner: microfocus

Published:

Updated: 2024-08-06T02:42:10.947Z

Reserved: 2016-11-03T00:00:00.000Z

Link: CVE-2016-9169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-03-23T06:59:00.640

Modified: 2026-05-13T00:24:29.033

Link: CVE-2016-9169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses