CVE-2012-3301: Input Validation
Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3301?
CVE-2012-3301 is classified as a moderate severity vulnerability due to its potential for HTTP response splitting attacks.
How do I fix CVE-2012-3301?
To fix CVE-2012-3301, upgrade IBM Lotus Domino to version 8.5.4 or later where the vulnerability is resolved.
What are the potential impacts of CVE-2012-3301?
The potential impacts of CVE-2012-3301 include the ability for attackers to inject arbitrary HTTP headers which can lead to various attacks, such as phishing and cache poisoning.
Which versions of IBM Lotus Domino are affected by CVE-2012-3301?
CVE-2012-3301 affects multiple versions of IBM Lotus Domino including all versions prior to 8.5.4.
Are any specific browsers affected by the vulnerabilities in CVE-2012-3301?
Yes, CVE-2012-3301 particularly affects Mozilla Firefox 3.0.9 and earlier versions, alongside unspecified browsers.