CVE-2012-4858
published 2013-03-05CVE-2012-4858: IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.87%
89.0th percentile
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cognos_business_intelligence | — | — |
| ibm | cognos_business_intelligence | — | — |
| ibm | cognos_business_intelligence | — | — |
| ibm | cognos_business_intelligence | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
ghsa5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x883-wq6q-rvfh: IBM Cognos Business Intelligence (BI) 8
ghsa_unreviewed·2022-05-17
CVE-2012-4858 [HIGH] CWE-20 GHSA-x883-wq6q-rvfh: IBM Cognos Business Intelligence (BI) 8
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors.
GHSA
Denial of Service in Apache Tomcat
ghsa·2022-05-04·CVSS 5.0
CVE-2012-0022 [MEDIUM] Denial of Service in Apache Tomcat
Denial of Service in Apache Tomcat
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
Red Hat
tomcat: large number of parameters DoS
vendor_redhat·2012-01-17·CVSS 5.0
CVE-2012-0022 [MEDIUM] tomcat: large number of parameters DoS
tomcat: large number of parameters DoS
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg21626697http://www-01.ibm.com/support/docview.wss?uid=swg24034373https://exchange.xforce.ibmcloud.com/vulnerabilities/79801http://www-01.ibm.com/support/docview.wss?uid=swg21626697http://www-01.ibm.com/support/docview.wss?uid=swg24034373https://exchange.xforce.ibmcloud.com/vulnerabilities/79801
2013-03-05
Published