CVE-2012-2292
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the Archer application, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
La política Silverlight cross-domain en EMC RSA Archer SmartSuite Framework v4.x y vRSA Archer GRC v5.x anterior a v5.2SP1 no restringe el acceso a la aplicación Archer, lo que permite a atacantes remotos eludir el Same Origin Policy mediante vectores desconocidos.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-04-19 CVE Reserved
- 2013-02-03 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-02/0001.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Rsa Archer Smartsuite Search vendor "Emc" for product "Rsa Archer Smartsuite" | 4.3 Search vendor "Emc" for product "Rsa Archer Smartsuite" and version "4.3" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Archer Smartsuite Search vendor "Emc" for product "Rsa Archer Smartsuite" | 4.5 Search vendor "Emc" for product "Rsa Archer Smartsuite" and version "4.5" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Archer Egrc Search vendor "Emc" for product "Rsa Archer Egrc" | 5.0 Search vendor "Emc" for product "Rsa Archer Egrc" and version "5.0" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Archer Egrc Search vendor "Emc" for product "Rsa Archer Egrc" | 5.1 Search vendor "Emc" for product "Rsa Archer Egrc" and version "5.1" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Archer Egrc Search vendor "Emc" for product "Rsa Archer Egrc" | 5.2 Search vendor "Emc" for product "Rsa Archer Egrc" and version "5.2" | - |
Affected
|