Novell iManager < 2.7.6 Patch 1 Multiple Vulnerabilities

critical Nessus Plugin ID 66036

Synopsis

The remote web application is affected by multiple vulnerabilities.

Description

The version of Novell iManager installed on the remote host is earlier than 2.7.6 Patch 1 and therefore affected by multiple vulnerabilities :

- There is an unspecified cross-site request forgery vulnerability. (CVE-2013-1088)

- A flaw exists due to the software not properly terminating session tokens after logout may allow an attacker with access to a user's network traffic to gain access to the account via a session replay attack.
(CVE-2013-3268)

Solution

Upgrade the Novell iManager 2.7.6 Patch 1 or higher.

See Also

https://support.microfocus.com/kb/doc.php?id=7010166

Plugin Details

Severity: Critical

ID: 66036

File Name: novell_imanager_csrf.nasl

Version: 1.8

Type: remote

Family: CGI abuses

Published: 4/19/2013

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2013-3268

Vulnerability Information

CPE: cpe:/a:novell:imanager

Required KB Items: www/novell_imanager

Exploit Ease: No known exploits are available

Patch Publication Date: 4/10/2013

Vulnerability Publication Date: 4/10/2013

Reference Information

CVE: CVE-2013-1088, CVE-2013-3268

BID: 59042, 59450