Novell Data Synchronizer Mobility Pack Multiple Remote Security Vulnerabilities
10 Apr. 2012
Summary
Novell Data Synchronizer Mobility Pack is prone to multiple remote security vulnerabilities, including cross-site scripting, information-disclosure, and session-fixation issues.
Vulnerable Systems:
* Novell Data Synchronizer Mobility Pack 1.1.2
* Novell Data Synchronizer Mobility Pack 1.1
* Novell Data Synchronizer Mobility Pack 1.0
Non-Vulnerable Systems:
* Novell Data Synchronizer Mobility Pack 1.2
Successful exploits of these vulnerabilities can allow attackers to execute arbitrary script code in a user's browser in the context of the webserver process, obtain sensitive data, or hijack a user's session.
Vendor Status:
Novell as issued an update for this vulnerablity.