PT-2011-1498 · Novell · Novell Identity Manager

Published

2011-01-07

·

Updated

2017-08-17

·

CVE-2010-4324

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Novell Identity Manager versions 3.7.0 through 370D
Description A cross-site scripting issue exists in the Approval Form of the User Application within the Roles Based Provisioning Module, allowing remote attackers to inject arbitrary web script or HTML.
Recommendations For versions 3.7.0 through 370D, update to a version after 370D to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4324

Affected Products

Novell Identity Manager