CVE-2012-0399: XSS
Published Mar 20, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
5 affected components
RSA EnVision=4.0-sp1
RSA EnVision=4.0-sp2
RSA EnVision=4.0-sp3
RSA EnVision=4.0-sp4
RSA EnVision=4.1
Event History
Mar 20, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0399?
The severity of CVE-2012-0399 is considered medium due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2012-0399?
To fix CVE-2012-0399, upgrade to RSA enVision version 4.1 or apply Patch 4 for versions below 4.1.
3
What are the affected versions in CVE-2012-0399?
CVE-2012-0399 affects RSA enVision versions 4.0 SP1 through SP4 and 4.1 before Patch 4.
4
What type of vulnerability is CVE-2012-0399?
CVE-2012-0399 is classified as a cross-site scripting (XSS) vulnerability.
5
Who can be affected by CVE-2012-0399?
Any user of RSA enVision 4.x prior to the security patch can be affected by CVE-2012-0399.