4.3
CVSSv3

CVE-2022-38756

Published: 16/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability has been identified in Micro Focus GroupWise Web in versions before 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microfocus groupwise

Exploits

Micro Focus GroupWise is a messaging software for email and personal information management Trovent Security GmbH discovered that the GroupWise web application transmits the session ID in HTTP GET requests in the URL when email content is accessed The exposed session ID can be recorded in the browser history of the client and in log files of the ...