CVE-2012-0734
published 2012-05-03CVE-2012-0734: IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive…
PriorityP430high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
1.30%
67.3th percentile
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly import jobs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted job.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
| ibm | rational_appscan | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1722 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
bugzilla·2012-06-12·CVSS 10.0
CVE-2012-1722 [CRITICAL] CVE-2012-1722 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
CVE-2012-1722 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
Java SE 6 Update 33 and Java SE 7 Update 5 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-1722). Upstream has CVSSv2 scored this issue as: 10/AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2012:0734 https://rhn.redhat.com/errata/RHSA-2012-0734.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:1019 https://rhn.redhat.com/errata/RHSA-2012-1019.html
---
This issue
Bugzilla
CVE-2012-1721 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
bugzilla·2012-06-12·CVSS 10.0
CVE-2012-1721 [CRITICAL] CVE-2012-1721 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
CVE-2012-1721 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
Java SE 6 Update 33 and Java SE 7 Update 5 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-1721). Upstream has CVSSv2 scored this issue as: 10/AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2012:0734 https://rhn.redhat.com/errata/RHSA-2012-0734.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2012:1019 https://rhn.redhat.com/errata/RHSA-2012-1019.html
---
This issue
Bugzilla
CVE-2012-0551 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
bugzilla·2012-06-12·CVSS 5.8
CVE-2012-0551 [MEDIUM] CVE-2012-0551 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
CVE-2012-0551 Oracle JDK: unspecified vulnerability fixed in 6u33 and 7u5 (Deployment)
Java SE 6 Update 33 and Java SE 7 Update 5 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-0551). Upstream has CVSSv2 scored this issue as: 5.8/AV:N/AC:M/Au:N/C:P/I:N/A:P
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2012:0734 https://rhn.redhat.com/errata/RHSA-2012-0734.html
---
It seems this CVE - CVE-2012-0551 - was previously used in Oracle CPU April 2012 for a GlassFish Enterprise Server, Web Container sub-component, CVSSv2 scored as 5.8/AV:N/AC:M/Au:N/C:P
http://secunia.com/advisories/48967http://secunia.com/advisories/48968http://www.ibm.com/support/docview.wss?uid=swg21592188http://www.securityfocus.com/bid/53247https://exchange.xforce.ibmcloud.com/vulnerabilities/74557http://secunia.com/advisories/48967http://secunia.com/advisories/48968http://www.ibm.com/support/docview.wss?uid=swg21592188http://www.securityfocus.com/bid/53247https://exchange.xforce.ibmcloud.com/vulnerabilities/74557
2012-05-03
Published