6.8

CVE-2013-1088

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Imanager Update sp6 Version <= 2.7
Novell ≫ Imanager Version 2.7
Novell ≫ Imanager Version 2.7 Update refresh6
Novell ≫ Imanager Version 2.7 Update sp4
Novell ≫ Imanager Version 2.7 Update sp4_patch1
Novell ≫ Imanager Version 2.7 Update sp4_patch2
Novell ≫ Imanager Version 2.7 Update sp4_patch3
Novell ≫ Imanager Version 2.7 Update sp4_patch4
Novell ≫ Imanager Version 2.7 Update sp5
Novell ≫ Imanager Version 2.7.1
Novell ≫ Imanager Version 2.7.2
Novell ≫ Imanager Version 2.7.3
Novell ≫ Imanager Version 2.7.3 Update ftf2
Novell ≫ Imanager Version 2.7.3 Update ftf4
Novell ≫ Imanager Version 2.7.3 Update sp3
Novell ≫ Imanager Version 2.7.4
Novell ≫ Imanager Version 2.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.444
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://www.novell.com/support/kb/doc.php?id=7010166
Vendor Advisory
https://bugzilla.novell.com/show_bug.cgi?id=726260