
CVE-2013-1096
https://notcve.org/view.php?id=CVE-2013-1096
28 Dec 2013 — Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId. Vulnerabilidad de cross-site scripting (XSS) en las funciones de la base 4.0.2 antes del Campo Patch D para Novell Identity Manager (también conocido como IDM) permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un taskDetail taskId. • http://download.novell.com/Download?buildid=dnDbmYe8PZc~ • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-1083
https://notcve.org/view.php?id=CVE-2013-1083
29 Mar 2013 — Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Manager (aka IDM) Roles Based Provisioning Module 4.0.2 before Field Patch C has unknown impact and attack vectors. Vulnerabilidad sin especificar en la funcionalidad de login en el Reporting Module en Novell Identity Manager (también conocido como IDM) Roles Based Provisioning Module v4.0.2 anterior a Field Patch C tiene un impacto y vectores de ataque desconocidos. • http://download.novell.com/Download?buildid=nbGXg-msbmw~ •

CVE-2011-2227
https://notcve.org/view.php?id=CVE-2011-2227
08 Oct 2011 — Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603. Vulnerabilidad de cross-site scripting (XSS) en Novell Identity Manager (también conocido como IDM) User Application v3.5.0, v3.5.1, v3.6.0, v3.6.1, v3.7.0 y ... • http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111710.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2011-1696
https://notcve.org/view.php?id=CVE-2011-1696
08 Oct 2011 — Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Novell Identity Manager (también conocido como IDM) User Application v3.5.0,... • http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111710.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2010-4324
https://notcve.org/view.php?id=CVE-2010-4324
07 Jan 2011 — Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Approval Form en User Application en Roles Based Provisioning Module v3.7.0 anteriores a 370D en Novell Identity Manager (también conocida como IDM) permite a ata... • http://osvdb.org/70298 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2008-5095
https://notcve.org/view.php?id=CVE-2008-5095
14 Nov 2008 — Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Novell User Application v3.0.1, v3.5.0, y v3.5.1; y Identity Manager Roles Based Provisioning Module v3.6.0 y v3.6.1 permite a atacantes remotos inyectar web script o HTML a través de vectores ... • http://www.novell.com/support/viewContent.do?externalId=7001157&sliceId=1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •