Novell Identity Manager Multiple Cross Site Scripting Vulnerabilities
BID:32924
Info
Novell Identity Manager Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 32924 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2008 12:00AM |
| Updated: | Dec 19 2008 04:21PM |
| Credit: | Novell |
| Vulnerable: |
Novell Identity Manager Roles Based Provisioning Module 3.6.1 Novell Identity Manager Roles Based Provisioning Module 3.6 Novell Identity Manager 3.5.1 Novell Identity Manager 3.0.1 Novell Identity Manager 3.5 |
| Not Vulnerable: | |
Discussion
Novell Identity Manager Multiple Cross Site Scripting Vulnerabilities
Novell Identity Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following are affected:
Identity Manager User Application 3.0.1
Identity Manager User Application 3.5.0
Identity Manager User Application 3.5.1
Identity Manager Roles Based Provisioning Module 3.6.0
Identity Manager Roles Based Provisioning Module 3.6.1
Novell Identity Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The following are affected:
Identity Manager User Application 3.0.1
Identity Manager User Application 3.5.0
Identity Manager User Application 3.5.1
Identity Manager Roles Based Provisioning Module 3.6.0
Identity Manager Roles Based Provisioning Module 3.6.1
Exploit / POC
Novell Identity Manager Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Novell Identity Manager Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor has released patches to address these issues. Please see the references for more information.
Solution:
The vendor has released patches to address these issues. Please see the references for more information.
References
Novell Identity Manager Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Novell Identity Manager (Novell)
- IDM Roles Based Provisioning Module 360 Field Patch D (Novell)
- IDM Roles Based Provisioning Module 361 Field Patch B (Novell)
- IDM User Application 301 Field Patch S (Novell)
- IDM User Application 350 Field Patch AE (Novell)
- IDM User Application 351 Field Patch W (Novell)