CVE-2011-2224: XSS
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2224?
CVE-2011-2224 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2011-2224?
To address CVE-2011-2224, you should update to Novell Mobility Pack version 1.2 or later, or apply any available patches.
What versions are affected by CVE-2011-2224?
CVE-2011-2224 affects Novell Mobility Pack versions prior to 1.2 and Novell Data Synchronizer versions 1.1.0 through 1.1.2.
What type of vulnerability is CVE-2011-2224?
CVE-2011-2224 is a cross-site scripting (XSS) vulnerability that exploits the absence of the HTTPOnly flag in the Set-Cookie header.
Who is vulnerable to CVE-2011-2224?
Organizations using affected versions of Novell Mobility Pack and Novell Data Synchronizer are vulnerable to CVE-2011-2224.