First published: Wed Apr 24 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell iManager | <=2.7 | |
Novell iManager | =2.7 | |
Novell iManager | =2.7-refresh6 | |
Novell iManager | =2.7-sp4 | |
Novell iManager | =2.7-sp4_patch1 | |
Novell iManager | =2.7-sp4_patch2 | |
Novell iManager | =2.7-sp4_patch3 | |
Novell iManager | =2.7-sp4_patch4 | |
Novell iManager | =2.7-sp5 | |
Novell iManager | =2.7.1 | |
Novell iManager | =2.7.2 | |
Novell iManager | =2.7.3 | |
Novell iManager | =2.7.3-ftf2 | |
Novell iManager | =2.7.3-ftf4 | |
Novell iManager | =2.7.3-sp3 | |
Novell iManager | =2.7.4 | |
Novell iManager | =2.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.