First published: Fri Jul 27 2012(Updated: )
Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Protector for Mail Security | =2.1 | |
IBM Lotus Protector for Mail Security | =2.5 | |
IBM Lotus Protector for Mail Security | =2.5.1 | |
IBM Lotus Protector for Mail Security | =2.8 | |
Ibm Proventia Network Mail Security System Firmware | =2.5 | |
Ibm Proventia Network Mail Security System Firmware | =2.5.0.2 | |
Ibm Proventia Network Mail Security System Firmware | =2.5.1 | |
Ibm Proventia Network Mail Security System Firmware | =2.6 | |
Ibm Proventia Network Mail Security System Firmware | =2.8 | |
IBM Proventia Network Mail Security System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2202 is considered a medium severity vulnerability due to its ability to allow unauthorized file access.
To fix CVE-2012-2202, you should upgrade to a patched version of IBM Lotus Protector for Mail Security or IBM Proventia Network Mail Security System firmware.
CVE-2012-2202 affects IBM Lotus Protector for Mail Security versions 2.1, 2.5, 2.5.1, and 2.8, as well as certain firmware versions of the IBM Proventia Network Mail Security System.
CVE-2012-2202 is a directory traversal vulnerability that allows remote authenticated administrators to read arbitrary files.
Yes, CVE-2012-2202 can be exploited remotely by authenticated users who can manipulate the template parameter.