Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-0204

Опубликовано: 31 янв. 2013
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Комментарий

Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426 Untrusted Search Path'

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:infosphere_import_export_manager:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_import_export_manager:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_import_export_manager:8.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_import_export_manager:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_import_export_manager:8.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_import_export_manager:9.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:8.5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server_metabrokers_\&_bridges:-:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.00676
Низкий

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

EPSS

Процентиль: 71%
0.00676
Низкий

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other