This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Novell First view 2005-12-31
Product Imanager Last view 2017-05-03
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:novell:imanager:2.7:sp2:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:1.5:*:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp4_patch4:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp4_patch2:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_3:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_4:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_5:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_6:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_7:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp1:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp4_patch3:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp3:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_1:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_8:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_10:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp6:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_2:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7_patch_9:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp7:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp5:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.0:*:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.0.2:*:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:*:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp4:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.7:sp4_patch1:*:*:*:*:*:* 8
cpe:2.3:a:novell:imanager:2.5:ir3:*:*:*:*:*:* 7
cpe:2.3:a:novell:imanager:2.5:*:*:*:*:*:*:* 7
cpe:2.3:a:novell:imanager:2.6.0:*:*:*:*:*:*:* 6
cpe:2.3:a:novell:imanager:2.7.0:*:*:*:*:*:*:* 6
cpe:2.3:a:novell:imanager:2.7:refresh6:*:*:*:*:*:* 5
cpe:2.3:a:novell:imanager:2.7.3:*:*:*:*:*:*:* 5
cpe:2.3:a:novell:imanager:2.7.3:ftf2:*:*:*:*:*:* 5
cpe:2.3:a:novell:imanager:2.7.2:*:*:*:*:*:*:* 4
cpe:2.3:a:novell:imanager:2.7.1:*:*:*:*:*:*:* 4
cpe:2.3:a:novell:imanager:2.7.3:ftf4:*:*:*:*:*:* 3
cpe:2.3:a:novell:imanager:2.7.3:sp3:*:*:*:*:*:* 3
cpe:2.3:a:novell:imanager:2.7.4:*:*:*:*:*:*:* 3
cpe:2.3:a:novell:imanager:2.7.5:*:*:*:*:*:*:* 2

Related : CVE

  Date Alert Description
9.8 2017-05-03 CVE-2017-7432

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.

8.8 2017-05-03 CVE-2017-7431

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.

6.1 2017-05-03 CVE-2017-7430

Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.

7.5 2017-04-27 CVE-2017-5186

Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.

10 2013-04-24 CVE-2013-3268

Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.

6.8 2013-04-24 CVE-2013-1088

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.

4 2012-04-09 CVE-2011-4188

Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929.

5 2010-06-28 CVE-2010-1930

Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.

9 2010-06-28 CVE-2010-1929

Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.

7.5 2010-01-08 CVE-2009-4486

Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema.

7.5 2008-08-06 CVE-2008-3488

Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.

7.8 2006-11-01 CVE-2006-4517

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference.

9.3 2005-12-31 CVE-2005-1730

Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.

CWE : Common Weakness Enumeration

%idName
25% (3) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
16% (2) CWE-352 Cross-Site Request Forgery (CSRF)
16% (2) CWE-189 Numeric Errors
8% (1) CWE-399 Resource Management Errors
8% (1) CWE-327 Use of a Broken or Risky Cryptographic Algorithm
8% (1) CWE-287 Improper Authentication
8% (1) CWE-264 Permissions, Privileges, and Access Controls
8% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

SAINT Exploits

Description Link
Novell iManager EnteredClassName buffer overflow More info here

Open Source Vulnerability Database (OSVDB)

id Description
65738 Novell iManager /nps/servlet/webacc/ Tree Parameter Off-by-One DoS
65737 Novell iManager /nps/servlet/webacc/ Multiple Parameter Overflow
61584 Novell iManager eDirectory Plugin Schema Information Handling Overflow
47278 Novell iManager Property Book Pages Arbitrary Plug-in Studio Deletion
29997 Novell iManager Tomcat HTTP POSTS TREE Variable DoS
3943 OpenSSL ASN.1 Parser Invalid Encoding DoS

ExploitDB Exploits

id Description
14010 Novell iManager Multiple Vulnerabilities

OpenVAS Exploits

id Description
2012-05-11 Name : Novell iManager jclient 'EnteredAttrName' Buffer Overflow Vulnerability
File : nvt/gb_novell_imanager_jclient_bof_vuln.nasl
2010-06-24 Name : Novell iManager < 2.7.4 Multiple Vulnerabilities
File : nvt/gb_novell_imanager_2_7_4.nasl
2010-01-11 Name : Novell iManager Importing/Exporting Schema Stack Buffer Overflow Vulnerability
File : nvt/novell_imanager_37672.nasl

Snort® IPS/IDS

Date Description
2019-09-24 Novell iManager buffer overflow attempt
RuleID : 51190 - Type : SERVER-WEBAPP - Revision : 1
2014-01-10 Novell iManager buffer overflow attempt
RuleID : 23354 - Type : SERVER-WEBAPP - Revision : 7
2014-01-10 Novell iManager Tree parameter denial of service attempt
RuleID : 19205 - Type : SERVER-OTHER - Revision : 10
2014-01-10 Novell iManager ClassName handling overflow attempt
RuleID : 18796 - Type : SERVER-WEBAPP - Revision : 10
2014-01-10 Novell iManager eDirectory plugin schema buffer overflow attempt - POST request
RuleID : 16430 - Type : SERVER-WEBAPP - Revision : 6
2014-01-10 Novell iManager eDirectory plugin schema buffer overflow attempt - GET request
RuleID : 16429 - Type : SERVER-WEBAPP - Revision : 6
2014-01-10 Novell iManager Tree parameter denial of service attempt
RuleID : 16052 - Type : SERVER-OTHER - Revision : 14

Nessus® Vulnerability Scanner

id Description
2013-04-19 Name: The remote web application is affected by multiple vulnerabilities.
File: novell_imanager_csrf.nasl - Type: ACT_GATHER_INFO
2012-08-29 Name: The remote directory service is affected by multiple vulnerabilities.
File: edirectory_88sp6_patch5.nasl - Type: ACT_GATHER_INFO
2008-08-12 Name: The remote web server is affected by a security bypass vulnerability.
File: novell_imgr_security_bypass_vuln.nasl - Type: ACT_GATHER_INFO
2004-09-29 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-136.nasl - Type: ACT_GATHER_INFO
2003-10-10 Name: The remote host is affected by a heap corruption vulnerability.
File: ssltest.nasl - Type: ACT_GATHER_INFO