Cross-Site Request Forgery in Novell iManager by Novell
CVE-2013-1088

Currently unrated

Key Information:

Vendor
Novell
Status
Vendor
CVE Published:
24 April 2013

Summary

The Novell iManager 2.7 software suffers from a Cross-Site Request Forgery (CSRF) vulnerability that enables remote attackers to exploit improper request validation in the iManager code. This weakness allows an attacker to hijack the authentication of users by sending crafted requests while masquerading as the legitimate user through an Apache Tomcat container. To mitigate the risk, users are encouraged to apply the latest security patches and review their access configurations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.