CVE-2022-38756

A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes a request to the Post Office Agent that contains sensitive information in the query parameters that could be logged by any intervening HTTP proxies.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microfocus:groupwise:*:*:*:*:*:*:*:*

History

18 Apr 2025, 14:15

Type Values Removed Values Added
References
  • () https://packetstorm.news/files/id/170768 -
  • () https://seclists.org/fulldisclosure/2023/Jan/28 -

21 Nov 2024, 07:17

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/170768/Micro-Focus-GroupWise-Session-ID-Disclosure.html - () http://packetstormsecurity.com/files/170768/Micro-Focus-GroupWise-Session-ID-Disclosure.html -
References () http://seclists.org/fulldisclosure/2023/Jan/28 - () http://seclists.org/fulldisclosure/2023/Jan/28 -
References () https://portal.microfocus.com/s/article/KM000012374?language=en_US - () https://portal.microfocus.com/s/article/KM000012374?language=en_US -
Summary
  • (es) Se ha identificado una vulnerabilidad en Micro Focus GroupWise Web en versiones anteriores a la 18.4.2. El componente web de GW realiza una solicitud al Agente de la oficina postal que contiene información confidencial en los parámetros de consulta que podrían registrar los servidores proxy HTTP que intervienen.

Information

Published : 2022-12-16 23:15

Updated : 2025-04-18 14:15


NVD link : CVE-2022-38756

Mitre link : CVE-2022-38756

CVE.ORG link : CVE-2022-38756


JSON object : View

Products Affected

microfocus

  • groupwise
CWE
CWE-532

Insertion of Sensitive Information into Log File