CVE-2011-2227
Summary
| CVE | CVE-2011-2227 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-08 02:52:00 UTC |
| Updated | 2011-11-22 03:56:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | CONFIRM | bugzilla.novell.com | |
| HTTP 404 Page Not Found | CONFIRM | support.novell.com | |
| HTTP 404 Page Not Found | CONFIRM | support.novell.com | |
| HTTP 404 Page Not Found | CONFIRM | support.novell.com | |
| Novell Identity Manager 'apwaDetail' Multiple Cross Site Scripting Vulnerabilities | BID | www.securityfocus.com | |
| HTTP 404 Page Not Found | CONFIRM | support.novell.com | |
| HTTP 404 Page Not Found | CONFIRM | support.novell.com | |
| HTTP 404 Page Not Found | CONFIRM | support.novell.com | |
| Novell Identity Manager Roles Based Provisioning Module Input Validation Flaw in 'apwaDetailId' Permits Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.