LOW · 3.5

CVE-2012-2202

Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticate...

Vulnerability Description

Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmLotus Protector For Mail Security2.1
IbmProventia Network Mail Security System Firmware2.5
IbmProventia Network Mail Security SystemAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2202?

CVE-2012-2202 is a vulnerability with a CVSS score of 3.5 (LOW). Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticate...

How severe is CVE-2012-2202?

CVE-2012-2202 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2202?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Lotus Protector For Mail Security, Ibm Proventia Network Mail Security System Firmware, Ibm Proventia Network Mail Security System.