First published: Tue Feb 21 2012(Updated: )
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech WebAccess | <=6.0 | |
Advantech WebAccess | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-0236 is considered to be low, mainly due to the vendor's assessment that it is not a security risk.
To fix CVE-2012-0236, upgrade to a patched version of Advantech WebAccess that addresses this vulnerability.
The potential impacts of CVE-2012-0236 include exposure of sensitive information through direct URL requests.
Advantech WebAccess versions 7.0 and earlier are affected by CVE-2012-0236.
Currently, no official workaround for CVE-2012-0236 has been provided by the vendor.