PT-2011-1498 · Novell · Novell Identity Manager
Publicado
2011-01-07
·
Atualizado
2017-08-17
·
CVE-2010-4324
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Novell Identity Manager versions 3.7.0 through 370D
Description
A cross-site scripting issue exists in the Approval Form of the User Application within the Roles Based Provisioning Module, allowing remote attackers to inject arbitrary web script or HTML.
Recommendations
For versions 3.7.0 through 370D, update to a version after 370D to resolve the issue.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Identity Manager