Novell Identity Manager Roles Based Provisioning Module taskId XSS

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

An application on the remote host is affected by a cross-site scripting
vulnerability.

Description :

According to its version, the Novell Identity Manager Roles Based
Provisioning Module install hosted on the remote web server is affected
by a reflected cross-site scripting vulnerability. This is due to
improper handling of user input to the 'taskId' parameter in the
'taskDetail.do' script. By tricking a user into clicking a specially
crafted URL, an attacker may be able to execute arbitrary script code in
a user's web browser in the security context of the affected
application.

See also :

http://www.nessus.org/u?0edefee8

Solution :

Apply Novell Identity Manager Roles Based Provisioning Module 4.0.2
Field Patch D.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 71847 ()

Bugtraq ID: 64500

CVE ID: CVE-2013-1096