First published: Wed May 03 2017(Updated: )
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Novell iManager | =2.7 | |
Novell iManager | =2.7-sp1 | |
Novell iManager | =2.7-sp2 | |
Novell iManager | =2.7-sp3 | |
Novell iManager | =2.7-sp4 | |
Novell iManager | =2.7-sp4_patch1 | |
Novell iManager | =2.7-sp4_patch2 | |
Novell iManager | =2.7-sp4_patch3 | |
Novell iManager | =2.7-sp4_patch4 | |
Novell iManager | =2.7-sp5 | |
Novell iManager | =2.7-sp6 | |
Novell iManager | =2.7-sp7 | |
Novell iManager | =2.7-sp7_patch_1 | |
Novell iManager | =2.7-sp7_patch_10 | |
Novell iManager | =2.7-sp7_patch_2 | |
Novell iManager | =2.7-sp7_patch_3 | |
Novell iManager | =2.7-sp7_patch_4 | |
Novell iManager | =2.7-sp7_patch_5 | |
Novell iManager | =2.7-sp7_patch_6 | |
Novell iManager | =2.7-sp7_patch_7 | |
Novell iManager | =2.7-sp7_patch_8 | |
Novell iManager | =2.7-sp7_patch_9 | |
NetIQ iManager | =3.0 | |
NetIQ iManager | =3.0.1 | |
NetIQ iManager | =3.0.2 | |
NetIQ iManager | =3.0.2.1 | |
NetIQ iManager | =3.0.3 | |
NetIQ iManager | =3.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7431 is considered to have a medium severity level due to its potential for persistent CSRF exploitation.
To fix CVE-2017-7431, upgrade to Novell iManager version 2.7 SP7 Patch 10 HF1 or NetIQ iManager version 3.0.3.1 or later.
CVE-2017-7431 makes persistent cross-site request forgery (CSRF) attacks possible against object management actions.
CVE-2017-7431 affects Novell iManager versions 2.7.x prior to SP7 Patch 10 HF1 and NetIQ iManager versions 3.x prior to 3.0.3.1.
Yes, vendors have released patches for CVE-2017-7431 that address the vulnerability in the affected iManager versions.