Vulnerabilities > Novell > Identity Manager Roles Based Provisioning Module > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-12-28 CVE-2013-1096 Cross-Site Scripting vulnerability in Novell Identity Manager Roles Based Provisioning Module 4.0.2
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.
network
novell CWE-79
4.3
2011-10-08 CVE-2011-2227 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.
network
novell CWE-79
4.3
2011-10-08 CVE-2011-1696 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 692972.
network
novell CWE-79
4.3
2011-01-07 CVE-2010-4324 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
novell CWE-79
4.3
2008-11-14 CVE-2008-5095 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
novell CWE-79
4.3