CVE-2011-2227: XSS
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2227?
CVE-2011-2227 has been assigned a medium severity rating due to its potential for exploitation via cross-site scripting (XSS).
How do I fix CVE-2011-2227?
To fix CVE-2011-2227, it is recommended to apply the latest security patches provided by Novell for the affected versions of the Identity Manager User Application and Roles Based Provisioning Module.
Which versions of Novell Identity Manager are affected by CVE-2011-2227?
CVE-2011-2227 affects Novell Identity Manager User Application versions 3.5.0 to 4.0.0 and Roles Based Provisioning Module versions 3.6.0 to 4.0.0.
What types of attacks can result from CVE-2011-2227?
CVE-2011-2227 can allow remote attackers to inject arbitrary web scripts or HTML into the affected applications, potentially leading to data theft or session hijacking.
Is CVE-2011-2227 a cross-site scripting vulnerability?
Yes, CVE-2011-2227 is identified as a cross-site scripting (XSS) vulnerability that can be exploited through user inputs.