CVE-2010-4322: XSS
Published Jan 7, 2011
·Updated
Cross-site scripting (XSS) vulnerability in gwtTeaming.rpc in Novell Vibe OnPrem 3 BETA allows remote authenticated users to inject arbitrary web script or HTML via the Micro Blog (aka What Are You Working On?) field.
Affected Software
1 affected component
Novell Vibe OnPrem=3-beta
Event History
Jan 7, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4322?
CVE-2010-4322 is classified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2010-4322?
To mitigate CVE-2010-4322, apply any available security patches from Novell or restrict user inputs to prevent XSS.
3
Who is affected by CVE-2010-4322?
CVE-2010-4322 affects remote authenticated users of Novell Vibe OnPrem version 3 beta.
4
What types of attacks can CVE-2010-4322 enable?
CVE-2010-4322 can enable an attacker to execute arbitrary web scripts or HTML within the user's browser session.
5
Is there a workaround for CVE-2010-4322?
As a temporary workaround for CVE-2010-4322, input validation and sanitization measures should be implemented.