2024-04-04 08:46:00 +00:00

119 lines
3.5 KiB
JSON

{
"id": "CVE-2010-4324",
"sourceIdentifier": "cve@mitre.org",
"published": "2011-01-07T19:00:17.983",
"lastModified": "2017-08-17T01:33:09.570",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the Approval Form in the User Application in the Roles Based Provisioning Module 3.7.0 before 370D in Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
},
{
"lang": "es",
"value": "Vulnerabilidad de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en Approval Form en User Application en Roles Based Provisioning Module v3.7.0 anteriores a 370D en Novell Identity Manager (tambi\u00e9n conocida como IDM) permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de\r\nvectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:novell:identity_manager:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2B15CB5E-A7FD-4917-9A7D-99598BEE202A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:novell:identity_manager_roles_based_provisioning_module:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.7.0",
"matchCriteriaId": "3609B364-9152-4448-A156-041BF5D289ED"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/70298",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42819",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5085293.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/45692",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1024941",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0038",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://bugzilla.novell.com/show_bug.cgi?id=653516",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64501",
"source": "cve@mitre.org"
}
]
}