CVE-2014-0600: Novell Groupwise

High severity, CVSS 7.8. EPSS: 3.1% chance of exploitation in the next 30 days.

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

Affected products

  • Novell Groupwise: version 2014 only

Published 2014-08-29. Last modified 2026-06-17.