Novell iManager 2.7.4

CPE Details

Novell iManager 2.7.4
2.7.4
2012-04-10
14h07 +00:00
2013-05-16
16h37 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:novell:imanager:2.7.4:*:*:*:*:*:*:*

Informations

Vendor

novell

Product

imanager

Version

2.7.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-1088 2013-04-24 08h00 +00:00 Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
6.8
CVE-2013-3268 2013-04-24 08h00 +00:00 Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
10
CVE-2011-4188 2012-04-09 18h00 +00:00 Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929.
4