Vulnerabilities > Novell > Imanager > 2.7.2

DATE CVE VULNERABILITY TITLE RISK
2013-04-24 CVE-2013-3268 Improper Authentication vulnerability in Novell Imanager
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
network
low complexity
novell CWE-287
critical
10.0
2013-04-24 CVE-2013-1088 Cross-Site Request Forgery (CSRF) vulnerability in Novell Imanager
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
network
novell CWE-352
6.8
2012-04-09 CVE-2011-4188 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Imanager
Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929.
network
low complexity
novell CWE-119
4.0
2010-01-08 CVE-2009-4486 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Novell Imanager
Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema.
network
low complexity
novell CWE-119
7.5