First published: Fri Jun 22 2012(Updated: )
The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Expeditor | =6.1 | |
IBM Expeditor | =6.1.1 | |
IBM Expeditor | =6.2 | |
IBM Expeditor | =6.2.1 | |
IBM Expeditor | =6.2.2 | |
IBM Expeditor | =6.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0191 is considered to have a moderate severity due to its potential for access control issues.
To fix CVE-2012-0191, upgrade to IBM Lotus Expeditor version 6.2 FP5 with Security Pack or later.
CVE-2012-0191 affects IBM Lotus Expeditor versions 6.1.x and 6.2.x prior to 6.2 FP5 with Security Pack.
CVE-2012-0191 allows remote attackers to spoof localhost request origins, posing a risk of unauthorized access.
Yes, CVE-2012-0191 involves security vulnerabilities within the web container of IBM Lotus Expeditor.