Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2013-1088

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.

  • Published: Apr 24, 2013
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-1088
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
novell / imanager 2.7-sp4 2.7-sp4.x
novell / imanager 2.7.4 2.7.4.x
novell / imanager 2.7 2.7.x
novell / imanager 2.7-refresh6 2.7-refresh6.x
novell / imanager 2.7.3-ftf2 2.7.3-ftf2.x
novell / imanager 2.7.1 2.7.1.x
novell / imanager 2.7.3 2.7.3.x
novell / imanager 2.7.5 2.7.5.x
novell / imanager 2.7.2 2.7.2.x
novell / imanager - 2.7.x
novell / imanager 2.7-sp5 2.7-sp5.x
novell / imanager 2.7-sp4_patch2 2.7-sp4_patch2.x
novell / imanager 2.7.3-ftf4 2.7.3-ftf4.x
novell / imanager 2.7-sp4_patch1 2.7-sp4_patch1.x
novell / imanager 2.7.3-sp3 2.7.3-sp3.x
novell / imanager 2.7-sp4_patch4 2.7-sp4_patch4.x
novell / imanager 2.7-sp4_patch3 2.7-sp4_patch3.x