RULE(RULE ID:316508)

Rule General Information
Release Date: 2016-09-08
Rule Name: Novell Groupwise Webaccess Cross-site Scripting Vulnerability -2 (CVE-2014-0611)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows
Reference: http://www.novell.com/support/kb/doc.php?id=7016653
https://bugzilla.novell.com/show_bug.cgi?id=909584
https://bugzilla.novell.com/show_bug.cgi?id=909586
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.novell.com/support/kb/doc.php?id=7016653