// For flags

CVE-2012-2202

IBM Proventia Network Mail Security System 2.5 - POST File Read

Severity Score

3.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.

Vulnerabilidad de salto de directorio en javatester_init.php en IBM Lotus Protector para Mail Security v2.1, v2.5, v2.5.1, y v2.8 e IBM ISS Proventia Network Mail Security System, permite a administradores autenticados remotamente leer archivos de su elección a través .. (punto punto) en el parámetro template.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-04-04 CVE Reserved
  • 2012-07-27 CVE Published
  • 2012-08-08 First Exploit
  • 2023-08-21 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Proventia Network Mail Security System Firmware
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware"
2.5
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5"
-
Affected
in Ibm
Search vendor "Ibm"
Proventia Network Mail Security System
Search vendor "Ibm" for product "Proventia Network Mail Security System"
*-
Safe
Ibm
Search vendor "Ibm"
Proventia Network Mail Security System Firmware
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware"
2.5.0.2
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5.0.2"
-
Affected
in Ibm
Search vendor "Ibm"
Proventia Network Mail Security System
Search vendor "Ibm" for product "Proventia Network Mail Security System"
*-
Safe
Ibm
Search vendor "Ibm"
Proventia Network Mail Security System Firmware
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware"
2.5.1
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5.1"
-
Affected
in Ibm
Search vendor "Ibm"
Proventia Network Mail Security System
Search vendor "Ibm" for product "Proventia Network Mail Security System"
*-
Safe
Ibm
Search vendor "Ibm"
Proventia Network Mail Security System Firmware
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware"
2.6
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.6"
-
Affected
in Ibm
Search vendor "Ibm"
Proventia Network Mail Security System
Search vendor "Ibm" for product "Proventia Network Mail Security System"
*-
Safe
Ibm
Search vendor "Ibm"
Proventia Network Mail Security System Firmware
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware"
2.8
Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.8"
-
Affected
in Ibm
Search vendor "Ibm"
Proventia Network Mail Security System
Search vendor "Ibm" for product "Proventia Network Mail Security System"
*-
Safe
Ibm
Search vendor "Ibm"
Lotus Protector For Mail Security
Search vendor "Ibm" for product "Lotus Protector For Mail Security"
2.1
Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Protector For Mail Security
Search vendor "Ibm" for product "Lotus Protector For Mail Security"
2.5
Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.5"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Protector For Mail Security
Search vendor "Ibm" for product "Lotus Protector For Mail Security"
2.5.1
Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.5.1"
-
Affected
Ibm
Search vendor "Ibm"
Lotus Protector For Mail Security
Search vendor "Ibm" for product "Lotus Protector For Mail Security"
2.8
Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.8"
-
Affected