Novell Identity Manager Roles Based Provisioning Module vulnerabilities

6 known vulnerabilities affecting novell/identity_manager_roles_based_provisioning_module.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2013-1096MEDIUMCVSS 4.3v4.0.22013-12-28
CVE-2013-1096 [MEDIUM] CWE-79 CVE-2013-1096: Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field P Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.
nvd
CVE-2013-1083CRITICALCVSS 10.0v4.0.22013-03-29
CVE-2013-1083 [CRITICAL] CVE-2013-1083: Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Mana Unspecified vulnerability in the login functionality in the Reporting Module in Novell Identity Manager (aka IDM) Roles Based Provisioning Module 4.0.2 before Field Patch C has unknown impact and attack vectors.
nvd
CVE-2011-2227MEDIUMCVSS 4.3v3.6.0v3.6.1+2 more2011-10-08
CVE-2011-2227 [MEDIUM] CWE-79 CVE-2011-2227: Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0 Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.
nvd
CVE-2011-1696MEDIUMCVSS 4.3v3.6.0v3.6.1+2 more2011-10-08
CVE-2011-1696 [MEDIUM] CWE-79 CVE-2011-1696: Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0 Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.
nvd
CVE-2010-4324MEDIUMCVSS 4.3≤ 3.7.02011-01-07
CVE-2010-4324 [MEDIUM] CWE-79 CVE-2010-4324: Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles B Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2008-5095MEDIUMCVSS 4.3v3.6.0v3.6.12008-11-14
CVE-2008-5095 [MEDIUM] CWE-79 CVE-2008-5095: Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd