First published: Fri Jan 07 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Identity Manager Roles Based Provisioning Module | <=3.7.0 | |
Micro Focus Identity Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4324 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2010-4324, upgrade to Novell Identity Manager Roles Based Provisioning Module version 3.7.0 or later.
CVE-2010-4324 affects Novell Identity Manager Roles Based Provisioning Module versions prior to 3.7.0.
CVE-2010-4324 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2010-4324 can be exploited remotely by attackers injecting arbitrary web scripts or HTML.