Vulnerabilities > Novell

DATE CVE VULNERABILITY TITLE RISK
2017-05-03 CVE-2017-7431 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
network
low complexity
novell netiq CWE-352
8.8
2017-05-03 CVE-2017-7430 Cross-site Scripting vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
network
low complexity
novell netiq CWE-79
6.1
2017-04-27 CVE-2017-5186 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
network
low complexity
netiq novell CWE-327
7.5
2017-04-20 CVE-2016-5762 Integer Overflow or Wraparound vulnerability in Novell Groupwise
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.
network
low complexity
novell CWE-190
critical
9.8
2017-04-20 CVE-2016-5761 Cross-site Scripting vulnerability in Novell Groupwise
Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.
network
low complexity
novell CWE-79
6.1
2017-04-20 CVE-2016-5760 Cross-site Scripting vulnerability in Novell Groupwise
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.
network
low complexity
novell CWE-79
6.1
2017-03-23 CVE-2016-9169 Cross-site Scripting vulnerability in Novell Groupwise 2014
A reflected XSS vulnerability exists in the web console of the Document Viewer Agent in Novell GroupWise before 2014 R2 Support Pack 1 Hot Patch 2 that may enable a remote attacker to execute JavaScript in the context of a valid user's browser session by getting the user to click on a specially crafted link.
network
low complexity
novell CWE-79
6.1
2017-03-23 CVE-2016-9168 Improper Input Validation vulnerability in Novell Edirectory
A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
network
low complexity
novell CWE-20
6.5
2017-03-23 CVE-2016-9167 Permissions, Privileges, and Access Controls vulnerability in Novell Edirectory
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
network
low complexity
novell CWE-264
7.5
2017-03-23 CVE-2016-5747 Improper Access Control vulnerability in Novell Edirectory
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
network
low complexity
novell CWE-284
7.5