4 results (0.011 seconds)

CVSS: 4.3EPSS: 0%CPEs: 10EXPL: 0

Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603. Vulnerabilidad de cross-site scripting (XSS) en Novell Identity Manager (también conocido como IDM) User Application v3.5.0, v3.5.1, v3.6.0, v3.6.1, v3.7.0 y v4.0.0, e Identity Manager Roles Based Provisioning Module v3.6.0, v3.6.1, v3.7.0,y v4.0.0, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro apwaDetail (también conocido como apwaDetailId), también conocido como Bug 709603. • http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111710.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111711.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112230.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112250.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112270.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112271.html http://www.securit • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 10EXPL: 0

Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Novell Identity Manager (también conocido como IDM) User Application v3.5.0, v3.5.1, v3.6.0, v3.6.1, v3.7.0, y v4.0.0, y Identity Manager Roles Based Provisioning Module v3.6.0, v3.6.1, v3.7.0, y v4.0.0, permite a atacantes remotos inyectar código web script o HTML a través del parámetro apwaDetail (también conocido como apwaDetailId), también conocido como Bug 692972. • http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111710.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111711.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112230.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112250.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112270.html http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112271.html http://www.securit • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en Approval Form en User Application en Roles Based Provisioning Module v3.7.0 anteriores a 370D en Novell Identity Manager (también conocida como IDM) permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://osvdb.org/70298 http://secunia.com/advisories/42819 http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5085293.html http://www.securityfocus.com/bid/45692 http://www.securitytracker.com/id?1024941 http://www.vupen.com/english/advisories/2011/0038 https://bugzilla.novell.com/show_bug.cgi?id=653516 https://exchange.xforce.ibmcloud.com/vulnerabilities/64501 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 0

Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Novell User Application v3.0.1, v3.5.0, y v3.5.1; y Identity Manager Roles Based Provisioning Module v3.6.0 y v3.6.1 permite a atacantes remotos inyectar web script o HTML a través de vectores desconocidos. • http://www.novell.com/support/viewContent.do?externalId=7001157&sliceId=1 http://www.securityfocus.com/bid/30947 http://www.securitytracker.com/id?1020792 http://www.securitytracker.com/id?1020793 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •