RULE(RULE ID:316845)

Rule General Information
Release Date: 2016-12-27
Rule Name: Micro Focus Groupwise Admin Console Install Login.jsp Cross Site Scripting Vulnerability -3 (CVE-2016-5760)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:92646
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://www.novell.com/support/kb/doc.php?id=7017973