Lucene search

K
cveRedhatCVE-2012-5586
HistoryDec 26, 2012 - 5:55 p.m.

CVE-2012-5586

2012-12-2617:55:02
CWE-264
redhat
web.nvd.nist.gov
27
drupal
services module
cve-2012-5586
security
vulnerability
nvd

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

55.3%

The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the “access user profiles” permission to access arbitrary users’ emails via vectors related to the “user index method” and “the path to the user resource.”

Affected configurations

Nvd
Node
marc_ingramservicesMatch6.x-3.0
OR
marc_ingramservicesMatch6.x-3.0alpha1
OR
marc_ingramservicesMatch6.x-3.0beta1
OR
marc_ingramservicesMatch6.x-3.0beta2
OR
marc_ingramservicesMatch6.x-3.0rc1
OR
marc_ingramservicesMatch6.x-3.0rc2
OR
marc_ingramservicesMatch6.x-3.0rc3
OR
marc_ingramservicesMatch6.x-3.0rc4
OR
marc_ingramservicesMatch6.x-3.0unstable1
OR
marc_ingramservicesMatch6.x-3.0unstable2
OR
marc_ingramservicesMatch6.x-3.0unstable3
OR
marc_ingramservicesMatch6.x-3.1
OR
marc_ingramservicesMatch6.x-3.2
OR
marc_ingramservicesMatch6.x-3.xdev
AND
drupaldrupalMatch-
Node
marc_ingramservicesMatch7.x-3.0
OR
marc_ingramservicesMatch7.x-3.0beta1
OR
marc_ingramservicesMatch7.x-3.0beta2
OR
marc_ingramservicesMatch7.x-3.0rc1
OR
marc_ingramservicesMatch7.x-3.0rc2
OR
marc_ingramservicesMatch7.x-3.0rc3
OR
marc_ingramservicesMatch7.x-3.0rc4
OR
marc_ingramservicesMatch7.x-3.0rc5
OR
marc_ingramservicesMatch7.x-3.0rc6
OR
marc_ingramservicesMatch7.x-3.1
OR
marc_ingramservicesMatch7.x-3.2
OR
marc_ingramservicesMatch7.x-3.3
OR
marc_ingramservicesMatch7.x-3.xdev
AND
drupaldrupalMatch-
VendorProductVersionCPE
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:*:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:alpha1:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:beta1:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:beta2:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:rc1:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:rc2:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:rc3:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:rc4:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:unstable1:*:*:*:*:*:*
marc_ingramservices6.x-3.0cpe:2.3:a:marc_ingram:services:6.x-3.0:unstable2:*:*:*:*:*:*
Rows per page:
1-10 of 281

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

55.3%

Related for CVE-2012-5586