CVE-2012-3302: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3302?
CVE-2012-3302 is classified as a medium severity vulnerability due to multiple cross-site scripting (XSS) issues.
How do I fix CVE-2012-3302?
To fix CVE-2012-3302, you should upgrade to IBM Lotus Domino version 8.5.4 or later.
What versions of IBM Lotus Domino are affected by CVE-2012-3302?
CVE-2012-3302 affects IBM Lotus Domino versions 7.x and 8.x prior to 8.5.4.
What type of attack is possible with CVE-2012-3302?
CVE-2012-3302 allows remote attackers to inject arbitrary web script or HTML via vulnerable URLs.
Is user interaction required to exploit CVE-2012-3302?
Yes, user interaction is generally required for exploiting the cross-site scripting vulnerabilities in CVE-2012-3302.