Novell.Sentinel.Log.Manager.Retention.Policy.Security.Bypass

description-logoDescription

This indicates an attack attempt to exploit a Security Bypass vulnerability in Novell Sentinel Log Manager.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. A remote attacker may be able to exploit this to create unauthorized data retention policies.

affected-products-logoAffected Products

Novell Sentinel Log Manager prior to 1.2.0.3

Impact logoImpact

Security Bypass: Remote attackers can bypass security checking of vulnerable systems.

recomended-action-logoRecommended Actions

Apply patch available from the vendor's website.
https://www.netiq.com/documentation/novelllogmanager12/log_manager_readme/data/log_manager_readme.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)