CVE-2012-2955
IBM Proventia Network Mail Security System 2.5 - POST File Read
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.
Múltiples vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en la interfaz de usuario administrativo de IBM Lotus Protector for Mail Security v2.1, v2.5, v2.5.1 y v2.8 e IBM ISS Proventia Network Mail Security System permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de la cadena de consulta.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-05-30 CVE Reserved
- 2012-07-20 CVE Published
- 2012-08-08 First Exploit
- 2023-06-10 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/84014 | Vdb Entry | |
http://secunia.com/advisories/49897 | Third Party Advisory | |
http://www-01.ibm.com/support/docview.wss?uid=swg21605626 | X_refsource_confirm | |
http://www.kb.cert.org/vuls/id/659791 | Third Party Advisory | |
http://www.securityfocus.com/bid/54486 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76798 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/20368 | 2012-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.5 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | * | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.5 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | ms3004 Search vendor "Ibm" for product "Proventia Network Mail Security System" and version "ms3004" | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.5.0.2 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5.0.2" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | * | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.5.0.2 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5.0.2" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | ms3004 Search vendor "Ibm" for product "Proventia Network Mail Security System" and version "ms3004" | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.5.1 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5.1" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | * | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.5.1 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.5.1" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | ms3004 Search vendor "Ibm" for product "Proventia Network Mail Security System" and version "ms3004" | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.6 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.6" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | * | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.6 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.6" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | ms3004 Search vendor "Ibm" for product "Proventia Network Mail Security System" and version "ms3004" | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.8 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.8" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | * | - |
Affected
|
Ibm Search vendor "Ibm" | Proventia Network Mail Security System Firmware Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" | 2.8 Search vendor "Ibm" for product "Proventia Network Mail Security System Firmware" and version "2.8" | - |
Affected
| in | Ibm Search vendor "Ibm" | Proventia Network Mail Security System Search vendor "Ibm" for product "Proventia Network Mail Security System" | ms3004 Search vendor "Ibm" for product "Proventia Network Mail Security System" and version "ms3004" | - |
Affected
|
Ibm Search vendor "Ibm" | Lotus Protector For Mail Security Search vendor "Ibm" for product "Lotus Protector For Mail Security" | 2.1 Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Protector For Mail Security Search vendor "Ibm" for product "Lotus Protector For Mail Security" | 2.5 Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Protector For Mail Security Search vendor "Ibm" for product "Lotus Protector For Mail Security" | 2.5.1 Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.5.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Lotus Protector For Mail Security Search vendor "Ibm" for product "Lotus Protector For Mail Security" | 2.8 Search vendor "Ibm" for product "Lotus Protector For Mail Security" and version "2.8" | - |
Affected
|