CVE-2012-3300
published 2012-09-25CVE-2012-3300: IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service…
PriorityP410low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
1.31%
67.4th percentile
IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| ibm | websphere_commerce | — | — |
| msrc | windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
vendor_msrc6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x74m-v27f-v796: IBM WebSphere Commerce 7
ghsa_unreviewed·2022-05-17
CVE-2012-3300 [LOW] GHSA-x74m-v27f-v796: IBM WebSphere Commerce 7
IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.
Microsoft
NetLogon Elevation of Privilege Vulnerability
vendor_msrc·2016-08-09·CVSS 6.8
CVE-2016-3300 [HIGH] NetLogon Elevation of Privilege Vulnerability
NetLogon Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows Netlogon improperly establishes a secure communications channel to a domain controller. An attacker who successfully exploited the vulnerability could run a specially crafted application on a domain-joined system.
To exploit the vulnerability, an attacker would require access to a domain-joined machine that points to a domain controller running either Windows Server 2012 or Windows Server 2012 R2.
The update addresses the vulnerability by modifying how Netlogon handles the establishment of secure channels.
Windows Authentication Methods: Windows Authentication Methods
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Rele
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1JR42771http://www.ibm.com/support/docview.wss?uid=swg21610909https://exchange.xforce.ibmcloud.com/vulnerabilities/77382http://www-01.ibm.com/support/docview.wss?uid=swg1JR42771http://www.ibm.com/support/docview.wss?uid=swg21610909https://exchange.xforce.ibmcloud.com/vulnerabilities/77382
2012-09-25
Published