CVE-2012-2203
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.
IBM Global Security Kit (también conocido como GSKit) anterior a v8.0.14.22, como se utiliza en IBM Directory Server Rational de IBM Tivoli Directory Server y otros productos, utiliza el formato PKCS # 12 para los objetos de archivo de certificado, sin exigir la integridad del archivo, lo que hace más fácil para a atacantes remotos falsificar servidores SSL a través de vectores relacionados con la inserción de una arbitraria raíz de Autoridad de Certificación (CA) de certificados
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-04 CVE Reserved
- 2012-08-08 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/51279 | Third Party Advisory | |
http://www.securityfocus.com/bid/54743 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77280 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV31973 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV31975 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21606145 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Global Security Kit Search vendor "Ibm" for product "Global Security Kit" | <= 8.0.13 Search vendor "Ibm" for product "Global Security Kit" and version " <= 8.0.13" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Global Security Kit Search vendor "Ibm" for product "Global Security Kit" | 7.0.4.28 Search vendor "Ibm" for product "Global Security Kit" and version "7.0.4.28" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Global Security Kit Search vendor "Ibm" for product "Global Security Kit" | 7.0.4.29 Search vendor "Ibm" for product "Global Security Kit" and version "7.0.4.29" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Rational Directory Server Search vendor "Ibm" for product "Rational Directory Server" | * | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Directory Server Search vendor "Ibm" for product "Tivoli Directory Server" | * | - |
Affected
|