First published: Fri Nov 14 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Identity Manager Roles Based Provisioning Module | =3.6.0 | |
Novell Identity Manager Roles Based Provisioning Module | =3.6.1 | |
Novell User Application | =3.0.1 | |
Novell User Application | =3.5.1 | |
Novell User Application | =3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-5095 is considered medium due to its potential impact on web application security through cross-site scripting.
To fix CVE-2008-5095, ensure that you upgrade to the latest version of the affected Novell User Application or Identity Manager Roles Based Provisioning Module where the vulnerability has been addressed.
CVE-2008-5095 affects Novell User Application versions 3.0.1, 3.5.0, 3.5.1 and Identity Manager Roles Based Provisioning Module versions 3.6.0, 3.6.1.
Yes, CVE-2008-5095 can allow remote attackers to execute arbitrary scripts, potentially leading to unauthorized access and data compromise.
No specific workaround for CVE-2008-5095 is provided, hence updating to a patched version is the recommended solution.