| Solutionary ID: SERT-VDN-1002 |
| CVE ID: CVE-2010-4322 |
| Product: Novell Vibe OnPrem 3 BETA Stored Cross-site Scripting Vulnerability |
| Application Vendor: Novell |
| Vendor URL: http://www.novell.com/products/vibe-onprem/ |
| Date discovered: 11/10/2010 |
| Discovered by: Rob Kraus, Paul Petefish, and Solutionary Engineering Research Team (SERT) |
| Vendor notification date: 12/3/2010 |
| Vendor response date: 12/3/2010 |
| Vendor acknowledgment date: 12/3/2010 |
| Public disclosure date: 12/10/2010 Exploit Vectors: Local and Remote Tested on: Cent OS 5.5 (kernel 2.6.18-194), MySQL Version 14.12 Distribution 5.0.77, and Novell Vibe 3 BETA OnPrem. Affected software versions: Vibe 3 BETA OnPrem Fixed in: Fixed in the final shipping version of Novell Vibe OnPrem 3 |
- Trusted Managed Security Provider | Solutionary
- Research
- Vulnerability Disclosures
- Novell Vibe OnPrem 3 BETA Stored Cross-site Scripting Vulnerability

