Loading
A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link. This could lead to session compromise or other browser-based attacks.
Use CWE-79, Novell vendor hub and Groupwise product page to widen CVE-2016-9169 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-0610, CVE-2013-0804 and CVE-2016-5762 for nearby disclosures in the same product family.