VYPR
Unrated severityNVD Advisory· Published May 22, 2009· Updated Apr 23, 2026

CVE-2009-1635

CVE-2009-1635

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple XSS vulnerabilities in Novell GroupWise WebAccess allow remote attackers to inject arbitrary script via the login page or HTML email.

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities exist in the WebAccess component of Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2. Attackers can inject arbitrary web script or HTML through three vectors: (1) the User.lang parameter on the login page (gw/webacc), (2) style expressions in a message containing an HTML file, and (3) bypass of insufficient scripting protections, such as by using whitespace between JavaScript event names and values [1][2][3].

Exploitation

An unauthenticated remote attacker can exploit these vulnerabilities by crafting a malicious URL to the login page with the User.lang parameter, or by sending a specially crafted HTML email to an authenticated user. In the latter case, the user must open the email within WebAccess to trigger the script execution. The attacker can also manipulate the login page via JavaScript to cause a denial-of-service condition [4]. No authentication is required for the login page vector; user interaction is required for the email-based vectors.

Impact

Successful exploitation allows the attacker to execute arbitrary script in the context of the victim's browser, potentially leading to session hijacking, credential theft, redirection to malicious sites, unauthorized access to the victim's mailbox, or defacement of the login page preventing legitimate logins [2][3][4].

Mitigation

Novell released fixes: GroupWise 7.x systems should apply GroupWise 7.03 Hot Patch 3 (HP3) or later; GroupWise 8.0 systems should apply GroupWise 8.0 Hot Patch 2 (HP2) or later [2][3][4]. There are no known workarounds; upgrading is the recommended action. This CVE is not listed on CISA's Known Exploited Vulnerabilities Catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

16
  • Novell/Groupwise16 versions
    cpe:2.3:a:novell:groupwise:7.0:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:novell:groupwise:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.01:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.02x:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.03:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.03:hp1a:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.03:hp2:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0:sp1:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:7.0:sp3:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:groupwise:8.0:hp1:*:*:*:*:*:*
    • (no CPE)range: <7.03 HP3, <8.0 HP2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.