Lucene search

K
cveIbmCVE-2012-2202
HistoryJul 27, 2012 - 10:27 a.m.

CVE-2012-2202

2012-07-2710:27:49
CWE-22
ibm
web.nvd.nist.gov
22
cve-2012-2202
directory traversal
ibm lotus protector
mail security
nvd
vulnerability
template parameter
remote authentication

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

71.0%

Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a … (dot dot) in the template parameter.

Affected configurations

Nvd
Node
ibmlotus_protector_for_mail_securityMatch2.1
OR
ibmlotus_protector_for_mail_securityMatch2.5
OR
ibmlotus_protector_for_mail_securityMatch2.5.1
OR
ibmlotus_protector_for_mail_securityMatch2.8
Node
ibmproventia_network_mail_security_system_firmwareMatch2.5
OR
ibmproventia_network_mail_security_system_firmwareMatch2.5.0.2
OR
ibmproventia_network_mail_security_system_firmwareMatch2.5.1
OR
ibmproventia_network_mail_security_system_firmwareMatch2.6
OR
ibmproventia_network_mail_security_system_firmwareMatch2.8
AND
ibmproventia_network_mail_security_system
VendorProductVersionCPE
ibmlotus_protector_for_mail_security2.1cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.1:*:*:*:*:*:*:*
ibmlotus_protector_for_mail_security2.5cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.5:*:*:*:*:*:*:*
ibmlotus_protector_for_mail_security2.5.1cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.5.1:*:*:*:*:*:*:*
ibmlotus_protector_for_mail_security2.8cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.8:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system_firmware2.5cpe:2.3:o:ibm:proventia_network_mail_security_system_firmware:2.5:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system_firmware2.5.0.2cpe:2.3:o:ibm:proventia_network_mail_security_system_firmware:2.5.0.2:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system_firmware2.5.1cpe:2.3:o:ibm:proventia_network_mail_security_system_firmware:2.5.1:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system_firmware2.6cpe:2.3:o:ibm:proventia_network_mail_security_system_firmware:2.6:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system_firmware2.8cpe:2.3:o:ibm:proventia_network_mail_security_system_firmware:2.8:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system*cpe:2.3:h:ibm:proventia_network_mail_security_system:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

71.0%

Related for CVE-2012-2202