Lucene search

K
cve[email protected]CVE-2012-5897
HistoryNov 17, 2012 - 9:55 p.m.

CVE-2012-5897

2012-11-1721:55:04
CWE-264
web.nvd.nist.gov
20
cve-2012-5897
ardoc activex control
quest intrust
remote attack
file overwrite
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.076 Low

EPSS

Percentile

94.2%

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

Affected configurations

NVD
Node
questintrustRange10.4.0.853
OR
questintrustMatch10.1
OR
questintrustMatch10.2.5
OR
questintrustMatch10.3
OR
questintrustMatch10.4

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.076 Low

EPSS

Percentile

94.2%

Related for CVE-2012-5897