-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2011.0085
A number of vulnerabilities have been identified in Novell Identity
Manager
                              10 October 2011

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Novell Identity Manager
Operating System:     Windows
                      SUSE
                      Red Hat
                      Solaris
Impact/Access:        Cross-site Scripting -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2011-2227 CVE-2011-1696 
Member content until: Wednesday, November  9 2011

OVERVIEW

        A number of vulnerabilities have been identified in Novell Identity
        Manager 3.7.0 prior to Field Patch E.


IMPACT

        The vendor has provided the following details regarding these
        vulnerabilities:
        
        "Potential XSS vulnerability in the apwaDetail
        Bug 692972 - XSS vulnerability found in apwaDetailId
        CVE-2011-1696
        
        Potential XSS vulnerability in the apwaDetail parameters
        Bug 709603 - XSS vulnerability found in apwaDetailId parameters
        CVE-2011-2227" [1]


MITIGATION

        The vendor recommends installing the latest patch to correct
        these issues. [1]


REFERENCES

        [1] IDM Roles Based Provisioning Module 370 Field Patch E
            http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5111711.html

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBTpJOie4yVqjM2NGpAQI6XRAAo2JZQphQRyfCtu3Iq6rUzoDWW2x+wby7
IDEyEXZ+agK6GmjsJlJ+FM8gIoEj7M0djOqF5ocmf+uGAQpaiFqe8IHY7uHkTVGn
m8xhv87/u6ndeLGUl0gyqDQ6Z7ZDfWTbNp9PWzgfaYgRJ7duO+d3vbaFboi4YjJm
3T23ie3O3Z7ghHOSgrWJWSPzyzX9kRTfx2/7+jVUt968qSYD1go8Bswru/aKj+0G
uvhNmcTuUrgpV6bZJbjUnCGuLLjg5oowEdFMA53gmjuyb7ABKhXZ8ATHMZIVAXg9
vrL5hGDpi69vHLwmlOOPNLyhRawn0es6/+lN/bkx7kNYe5HuZGUJbaolpeV5cu1l
QAi9JfDjJ8WHqVxaFU/CfT1sweBewsUSI79wiVVWits9KYziveOWcc6GU2ICMPWR
dZcebavZsBieyN8i2bEM/dZwJdTrQOBxK5g4a+9a86iR20eScZjhQg+oo2MZZz5y
ozksS2MAW9d3vuAVjTQWYtGR9O63T0a/7y1VxOhWH2Iu+ysxNEXN630xEbURSt23
l/9Bo4UqXXImvKCEwvYlfJ5+IMxjIeaEVPa8sbnSZpmCfZScbUdUeHV83Z33STBc
uNjmGYDt1ao1uMWCGhuVM25iDkN3edyBcIaTT2ZSebtYuQtrX1KGGdF3IjWU5IVI
EvMiR50bn1g=
=HkYE
-----END PGP SIGNATURE-----