Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference.
| Software | From | Fixed in |
|---|---|---|
| novell / imanager | 2.0.2 | 2.0.2.x |
| novell / imanager | 2.0 | 2.0.x |
| novell / imanager | 1.5 | 1.5.x |
| novell / imanager | - | 2.5.x |