Micro Focus GroupWise Post Office Agent Buffer Overflow

Strike ID:
E16-7g201
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2016

Description

This strike exploits a vulnerability in Micro Focus GroupWise Post Office Agent. An integer overflow can lead to a heap buffer overlflow in the GroupWise Post Office Agent. If an un-authenticated user sends a login request with an overly large username or password to the agent a buffer is overflown. This then leads to a denial of service condition, and can potentially allow for remote code execution to occur.

CVE

References

Bid