Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
References
Link | Resource |
---|---|
https://www.novell.com/support/kb/doc.php?id=7010166 | Release Notes Vendor Advisory |
https://www.netiq.com/support/kb/doc.php?id=7016795 | Release Notes Vendor Advisory |
https://dl.netiq.com/Download?buildid=wpS1UqIlx-o~ | Release Notes Vendor Advisory |
https://dl.netiq.com/Download?buildid=24FxpmqdThE~ | Release Notes Vendor Advisory |
https://bugzilla.novell.com/show_bug.cgi?id=1030692 | Permissions Required |
https://bugzilla.novell.com/show_bug.cgi?id=1024963 | Permissions Required |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2017-05-02 22:59
Updated : 2017-05-15 11:53
NVD link : CVE-2017-7431
Mitre link : CVE-2017-7431
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
novell
- imanager
netiq
- imanager