Cross-Site Scripting Vulnerability in Novell Identity Manager and Roles Based Provisioning Module
CVE-2011-1696
Currently unrated
Key Information:
- Vendor
Novell
- Vendor
- CVE Published:
- 8 October 2011
What is CVE-2011-1696?
A cross-site scripting (XSS) vulnerability exists in Novell Identity Manager User Application and its Roles Based Provisioning Module, allowing remote attackers to inject arbitrary web scripts or HTML via a maliciously crafted request targeting the apwaDetail parameter. This exploitation could lead to the unauthorized execution of scripts in the context of the user’s session, potentially compromising sensitive information and the integrity of web applications.