Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

private SSL key embedded in JAR file in iManager

Disclosure Date: March 02, 2018 (last updated November 08, 2023)
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
0
Attacker Value
Unknown

CVE-2013-3268

Disclosure Date: April 24, 2013 (last updated October 05, 2023)
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2013-1088

Disclosure Date: April 24, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.
0
Attacker Value
Unknown

CVE-2009-4486

Disclosure Date: January 08, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema.
0