CVE-2013-1088: Novell Imanager

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.

Affected products

  • Novell Imanager: up to and including 2.7; version 2.7 only; version 2.7.1 only; version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; …

Published 2013-04-24. Last modified 2026-06-16.