Vulnerabilities > Novell > Identity Manager

DATE CVE VULNERABILITY TITLE RISK
2016-10-27 CVE-2016-1598 Cross-site Scripting vulnerability in Novell products
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
network
low complexity
novell CWE-79
5.4
2011-01-07 CVE-2010-4324 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
novell CWE-79
4.3
2010-09-08 CVE-2010-3264 Credentials Management vulnerability in Novell Identity Manager 3.6.1
The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.
local
low complexity
novell CWE-255
2.1
2008-01-04 CVE-2007-6625 USE of Externally-Controlled Format String vulnerability in Novell Identity Manager 3.5.1
The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.
network
low complexity
novell CWE-134
5.0