Unrated severityNVD Advisory· Published Mar 3, 2010· Updated Jun 16, 2026
CVE-2009-4662
CVE-2009-4662
Description
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:novell:groupwise:7.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:novell:groupwise:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:novell:groupwise:7.01:*:*:*:*:*:*:*
- cpe:2.3:a:novell:groupwise:7.03:*:*:*:*:*:*:*
- cpe:2.3:a:novell:groupwise:7.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:novell:groupwise:7.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:novell:groupwise:7.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:novell:groupwise:8.0:*:*:*:*:*:*:*
- (no CPE)range: 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1
Patches
Vulnerability mechanics
References
6- secunia.com/advisories/36746nvdVendor Advisory
- www.novell.com/support/viewContent.donvdVendor Advisory
- www.vupen.com/english/advisories/2009/2689nvdVendor Advisory
- www.securityfocus.com/bid/36437nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53322nvd
News mentions
0No linked articles in our index yet.