« Volver al listado

CVE-2013-1088

Estado: ModificadaMedia (6.8)—

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1088",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-04-24T10:28:37.790",
  "references": [
    {
      "url": "http://www.novell.com/support/kb/doc.php?id=7010166",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=726260",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/support/kb/doc.php?id=7010166",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.novell.com/show_bug.cgi?id=726260",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de tipo cross-site request forgery (CSRF) en iManager de Novell versión 2.7 anterior a SP6 Parche 1, permite a los atacantes remotos secuestrar la autenticación de usuarios arbitrarios mediante el aprovechamiento de la comprobación incorrecta de peticiones para código desplegado de iManager dentro de un contenedor Apache Tomcat."
    }
  ],
  "lastModified": "2026-06-16T23:50:49.780",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:imanager:*:sp6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58461B54-58CA-4C0C-BE64-7D9F1012A33C",
              "versionEndIncluding": "2.7"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B982AA70-B5BA-4E56-8DBE-15EEC0A70DA5"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:refresh6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8303A14-6DF5-4A65-A570-154A7A2FECDF"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C62EA146-9EFC-4CDC-96A7-E44CC0744B83"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:sp4_patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "155397A8-932C-40EC-B763-AC39D5B8B736"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:sp4_patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DBD982A-EF73-403E-B486-BBECBCE606BA"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:sp4_patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "096ADACF-B48F-4636-B141-4D680F498A49"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:sp4_patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "724BD98B-2407-4B8D-8892-A39B965249BC"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F0B8EAE-210E-4AB8-9373-B8FC1216C056"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87E03D12-D745-4071-A309-3E2DD2CC5BE7"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0CBA9BF-C7F3-4CBB-92A8-DB554056ADD4"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50360B96-A5EB-48BE-A6B5-DE7D3ECA3CFB"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.3:ftf2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01F00C86-B0C3-4C7D-855F-466F63153712"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.3:ftf4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B39D2B9-2F31-4930-B356-6F315CA34EED"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.3:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57C73F10-944E-4366-A02D-FC1AE155E073"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "867A2FDB-5C1A-4A09-8856-9F055BDE9F28"
            },
            {
              "criteria": "cpe:2.3:a:novell:imanager:2.7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DA65B98-93B7-4EBF-A630-DA67D71DEEA3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}