Novell GroupWise and the July 2012 Oracle "Outside In" Security Vulnerabilities

  • 7010569
  • 03-Aug-2012
  • 15-Jan-2013

Environment

GroupWise 8.0x up to and including 8.0.3
GroupWise 2012.0
Previous versions of GroupWise are likely also vulnerable but are no longer supported. Customers on earlier versions of GroupWise should, at a minimum, upgrade their GroupWise agents to version 8.0 Support Pack 3 Hot Patch 1 or 2012 SP1 in order to secure their system.

Situation

On July 17, 2012, US-CERT disclosed multiple security vulnerabilities in the Oracle "Outside In" viewer technology that is licensed by Novell for use in GroupWise. 

For more information on these vulnerabilities, please see the security advisory from the U.S. CERT team: http://www.kb.cert.org/vuls/id/118913

CVE-2012-1766, CVE-2012-1767, CVE-2012-1768, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, CVE-2012-3109, CVE-2012-3110

Resolution

Novell has received updated software from Oracle to address these security issues on the Windows and Linux platforms. 

NOTE: The updated viewers from Oracle are included with the GroupWise 8.0.3 HP1 and 2012 SP1 clients for Windows, and the 8.0.3 HP1 and 2012 SP1 agents for Windows and Linux servers.  Novell has made available a separate download for the NetWare viewers.  They can be found at https://download.novell.com/Download?buildid=i_DOXopug2Q~

Status

Security Alert

Bug Number

773740 773535