Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
References
Link | Resource |
---|---|
http://www.novell.com/support/kb/doc.php?id=7010166 | Vendor Advisory |
https://bugzilla.novell.com/show_bug.cgi?id=726260 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2013-04-24T10:00:00
Updated: 2013-04-27T09:00:00
Reserved: 2013-01-11T00:00:00
Link: CVE-2013-1088
JSON object: View
NVD Information
Status : Analyzed
Published: 2013-04-24T10:28:37.790
Modified: 2013-05-16T04:00:00.000
Link: CVE-2013-1088
JSON object: View
Redhat Information
No data.
CWE