Vulnerability Description
Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advance Productivity Software | Dte Axiom | <= 12.3.2 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2012/Sep/62
- http://secunia.com/advisories/50508Vendor Advisory
- http://www.osvdb.org/85499
- http://seclists.org/fulldisclosure/2012/Sep/62
- http://secunia.com/advisories/50508Vendor Advisory
- http://www.osvdb.org/85499
FAQ
What is CVE-2012-2455?
CVE-2012-2455 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and...
How severe is CVE-2012-2455?
CVE-2012-2455 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2455?
Check the references section above for vendor advisories and patch information. Affected products include: Advance Productivity Software Dte Axiom.