Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Novell IDM Cross Site Scripting and HTML Injection Vulnerabilities

Novell User Application and Identity Manager Roles Based Provisioning Module are prone to multiple security vulnerabilities, including multiple HTML-injection issues and a cross-site scripting issue.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user. Other attacks are also possible.

The following versions of Novell User Application are vulnerable:

3.0.1
3.5.0
3.5.1

The following versions of Novell Identity Manager Roles Based Provisioning Module are vulnerable:

3.6.0
3.6.1







 

Privacy Statement
Copyright 2009, SecurityFocus