Novell
Novell Imanager: vulnerabilidades y CVE
Novell Imanager tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-7432 | Crítica (9.8) | 1.5% | — | 3 may 2017 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability. |
| CVE-2017-7431 | Alta (8.8) | 0.58% | — | 3 may 2017 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management. |
| CVE-2017-7430 | Media (6.1) | 1.0% | — | 3 may 2017 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework. |
| CVE-2017-5186 | Alta (7.5) | 0.65% | — | 27 abr 2017 | Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing… |
| CVE-2013-3268 | Alta (10) | 1.6% | — | 24 abr 2013 | Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors. |
| CVE-2013-1088 | Media (6.8) | 0.61% | — | 24 abr 2013 | Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager… |
| CVE-2011-4188 | Media (4) | 1.5% | — | 9 abr 2012 | Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other… |
| CVE-2010-1930 | Media (5) | 8.3% | — | 28 jun 2010 | Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc. |
| CVE-2010-1929 | Alta (9) | 16% | — | 28 jun 2010 | Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated… |
| CVE-2009-4486 | Alta (7.5) | 4.3% | — | 8 ene 2010 | Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related… |
| CVE-2008-3488 | Alta (7.5) | 1.4% | — | 6 ago 2008 | Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors. |
| CVE-2006-4517 | Alta (7.8) | 3.2% | — | 1 nov 2006 | Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference. |
| CVE-2005-1730 | Alta (9.3) | 4.8% | — | 31 dic 2005 | Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL… |
| CVE-2004-0079 | Alta (7.5) | 9.5% | — | 23 nov 2004 | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. |
| CVE-2004-0112 | Media (5) | 10% | — | 23 nov 2004 | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a… |
| CVE-2004-0081 | Media (5) | 7.2% | — | 23 nov 2004 | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. |
Otros productos de Novell
Suse Linux Enterprise Server · 91Suse Linux Enterprise Desktop · 83Groupwise · 75Netware · 72Suse Linux Enterprise Software Development KIT · 65Edirectory · 51Zenworks Configuration Management · 35Suse Linux Enterprise Real Time Extension · 33Iprint · 30Suse Linux Enterprise Debuginfo · 24Suse Linux Enterprise Workstation Extension · 24Suse Linux Enterprise Live Patching · 22