Novell GroupWise and the July 2012 Oracle "Outside In" Security Vulnerabilities

  • 7010569
  • 03-Aug-2012
  • 15-Jan-2013


GroupWise 8.0x up to and including 8.0.3
GroupWise 2012.0
Previous versions of GroupWise are likely also vulnerable but are no longer supported. Customers on earlier versions of GroupWise should, at a minimum, upgrade their GroupWise agents to version 8.0 Support Pack 3 Hot Patch 1 or 2012 SP1 in order to secure their system.


On July 17, 2012, US-CERT disclosed multiple security vulnerabilities in the Oracle "Outside In" viewer technology that is licensed by Novell for use in GroupWise. 

For more information on these vulnerabilities, please see the security advisory from the U.S. CERT team:

CVE-2012-1766, CVE-2012-1767, CVE-2012-1768, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, CVE-2012-3109, CVE-2012-3110


Novell has received updated software from Oracle to address these security issues on the Windows and Linux platforms. 

NOTE: The updated viewers from Oracle are included with the GroupWise 8.0.3 HP1 and 2012 SP1 clients for Windows, and the 8.0.3 HP1 and 2012 SP1 agents for Windows and Linux servers.  Novell has made available a separate download for the NetWare viewers.  They can be found at


Security Alert

Bug Number

773740 773535