Lucene search

K
cveIbmCVE-2012-4832
HistoryJan 31, 2013 - 12:06 p.m.

CVE-2012-4832

2013-01-3112:06:18
CWE-200
ibm
web.nvd.nist.gov
23
ibm
infosphere
isf
information server
vulnerability
nvd
security
remote attack
authentication
unattended workstation

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

58.8%

Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Affected configurations

Nvd
Node
ibminfosphere_business_glossaryMatch8.1.1
OR
ibminfosphere_business_glossaryMatch8.1.2
OR
ibminfosphere_information_serverMatch8.1
OR
ibminfosphere_information_serverMatch8.5
OR
ibminfosphere_information_serverMatch8.5.0.1
OR
ibminfosphere_information_serverMatch8.5.0.2
OR
ibminfosphere_information_serverMatch8.7
VendorProductVersionCPE
ibminfosphere_business_glossary8.1.1cpe:2.3:a:ibm:infosphere_business_glossary:8.1.1:*:*:*:*:*:*:*
ibminfosphere_business_glossary8.1.2cpe:2.3:a:ibm:infosphere_business_glossary:8.1.2:*:*:*:*:*:*:*
ibminfosphere_information_server8.1cpe:2.3:a:ibm:infosphere_information_server:8.1:*:*:*:*:*:*:*
ibminfosphere_information_server8.5cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
ibminfosphere_information_server8.5.0.1cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*
ibminfosphere_information_server8.5.0.2cpe:2.3:a:ibm:infosphere_information_server:8.5.0.2:*:*:*:*:*:*:*
ibminfosphere_information_server8.7cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

58.8%

Related for CVE-2012-4832