Cross-Site Scripting Vulnerability in Novell Identity Manager and Roles Based Provisioning Module
CVE-2011-1696

Currently unrated

What is CVE-2011-1696?

A cross-site scripting (XSS) vulnerability exists in Novell Identity Manager User Application and its Roles Based Provisioning Module, allowing remote attackers to inject arbitrary web scripts or HTML via a maliciously crafted request targeting the apwaDetail parameter. This exploitation could lead to the unauthorized execution of scripts in the context of the user’s session, potentially compromising sensitive information and the integrity of web applications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.