Persistent CSRF Vulnerability in Novell iManager and NetIQ iManager
CVE-2017-7431
8.8HIGH
Key Information:
- Vendor
- Novell
- Vendor
- CVE Published:
- 3 May 2017
Summary
A persistent Cross-Site Request Forgery (CSRF) vulnerability exists in Novell iManager versions 2.7.x prior to 2.7 SP7 Patch 10 HF1, and in NetIQ iManager versions 3.x prior to 3.0.3.1. This vulnerability allows an attacker to exploit an authenticated session to perform unauthorized actions on behalf of the user without their consent. Organizations are advised to apply the latest patches to mitigate potential security risks.
Affected Version(s)
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved