Novell Sentinel Log Manager Retention Policy Security Bypass Vulnerability

Summary
The host is running Novell Sentinel Log Manager and is prone security bypass vulnerability.
Impact
Successful exploitation will allow attackers to bypass certain security restrictions. Impact Level: Application
Solution
Apply the patch or upgrade to 1.2.0.3 or later, https://www.netiq.com/products/sentinel-log-manager/
Insight
The flaw is due to an error when saving a retention policy and can be exploited by a report administrator (read only role) to create new policies.
Affected
Novell Sentinel Log Manager version 1.2.0.2 and prior
References