10

CVE-2013-3268

Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Imanager Update sp6 Version <= 2.7
Novell ≫ Imanager Version 2.7 Update refresh6
Novell ≫ Imanager Version 2.7 Update sp4
Novell ≫ Imanager Version 2.7 Update sp4_patch1
Novell ≫ Imanager Version 2.7 Update sp4_patch2
Novell ≫ Imanager Version 2.7 Update sp4_patch3
Novell ≫ Imanager Version 2.7 Update sp4_patch4
Novell ≫ Imanager Version 2.7 Update sp5
Novell ≫ Imanager Version 2.7.0
Novell ≫ Imanager Version 2.7.1
Novell ≫ Imanager Version 2.7.2
Novell ≫ Imanager Version 2.7.3
Novell ≫ Imanager Version 2.7.3 Update ftf2
Novell ≫ Imanager Version 2.7.3 Update ftf4
Novell ≫ Imanager Version 2.7.3 Update sp3
Novell ≫ Imanager Version 2.7.4
Novell ≫ Imanager Version 2.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.64% 0.732
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://www.novell.com/support/kb/doc.php?id=7010166
http://www.securityfocus.com/bid/59450
https://bugzilla.novell.com/show_bug.cgi?id=807429
https://exchange.xforce.ibmcloud.com/vulnerabilities/83761