CVE-2011-2227
Novell Identity Manager Cross-Site Scripting via apwaDetail Parameter
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to inject arbitrary web script or HTML via the apwaDetail (aka apwaDetailId) parameter, aka Bug 709603.
References (9)
Core 9
Core References
Vendor Advisory x_refsource_confirm
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112271.html
Vendor Advisory x_refsource_confirm
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111710.html
Vendor Advisory x_refsource_confirm
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112230.html
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=709603
Vendor Advisory x_refsource_confirm
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111711.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1026138
Vendor Advisory x_refsource_confirm
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112250.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49935
Vendor Advisory x_refsource_confirm
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5112270.html
Scores
EPSS
0.0066
EPSS Percentile
71.3%
Details
CWE
CWE-79
Status
published
Products (10)
novell/identity_manager_roles_based_provisioning_module
3.6.0
novell/identity_manager_roles_based_provisioning_module
3.6.1
novell/identity_manager_roles_based_provisioning_module
3.7.0
novell/identity_manager_roles_based_provisioning_module
4.0.0
novell/identity_manager_user_application
3.5.0
novell/identity_manager_user_application
3.5.1
novell/identity_manager_user_application
3.6.0
novell/identity_manager_user_application
3.6.1
novell/identity_manager_user_application
3.7.0
novell/identity_manager_user_application
4.0.0
Published
Oct 08, 2011
Tracked Since
Feb 18, 2026