CVE-2012-0236: Infoleak
Published Feb 21, 2012
·Updated
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
Affected Software
2 affected components
Advantech Advantech WebAccess<=6.0
Advantech Advantech WebAccess=5.0
Remediation
Event History
Feb 21, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0236?
The severity of CVE-2012-0236 is considered to be low, mainly due to the vendor's assessment that it is not a security risk.
2
How do I fix CVE-2012-0236?
To fix CVE-2012-0236, upgrade to a patched version of Advantech WebAccess that addresses this vulnerability.
3
What are the potential impacts of CVE-2012-0236?
The potential impacts of CVE-2012-0236 include exposure of sensitive information through direct URL requests.
4
Which versions of Advantech WebAccess are affected by CVE-2012-0236?
Advantech WebAccess versions 7.0 and earlier are affected by CVE-2012-0236.
5
Is there a workaround for CVE-2012-0236?
Currently, no official workaround for CVE-2012-0236 has been provided by the vendor.