Vulnerability Description
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
CVSS Score
10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell | Imanager | <= 2.7 |
Related Weaknesses (CWE)
References
- http://www.novell.com/support/kb/doc.php?id=7010166
- http://www.securityfocus.com/bid/59450
- https://bugzilla.novell.com/show_bug.cgi?id=807429
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83761
- http://www.novell.com/support/kb/doc.php?id=7010166
- http://www.securityfocus.com/bid/59450
- https://bugzilla.novell.com/show_bug.cgi?id=807429
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83761
FAQ
What is CVE-2013-3268?
CVE-2013-3268 is a vulnerability with a CVSS score of 10.0 (HIGH). Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
How severe is CVE-2013-3268?
CVE-2013-3268 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3268?
Check the references section above for vendor advisories and patch information. Affected products include: Novell Imanager.