cbcvebase.

Ibm Lotus Protector For Mail Security vulnerabilities

7 known vulnerabilities affecting ibm/lotus_protector_for_mail_security.

Total CVEs
7
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3LOW2

Vulnerabilities

Page 1 of 1
CVE-2012-2202P4LOWCVSS 3.5PoCv2.1v2.5+2 more2012-07-27
CVE-2012-2202 [LOW] CWE-22 CVE-2012-2202: Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2. Directory traversal vulnerability in javatester_init.php in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the template parameter.
nvd
CVE-2012-2955P4MEDIUMCVSS 4.3PoCv2.1v2.5+2 more2012-07-20
CVE-2012-2955 [MEDIUM] CWE-79 CVE-2012-2955: Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotu Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string.
nvd
CVE-2014-0887P3HIGHCVSS 7.1v2.8v2.8.12014-03-25
CVE-2014-0887 [HIGH] CWE-78 CVE-2014-0887: The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote aut The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
nvd
CVE-2014-0886P4HIGHCVSS 7.1v2.8v2.8.12014-03-25
CVE-2014-0886 [HIGH] CWE-78 CVE-2014-0886: The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote aut The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.
nvd
CVE-2014-0885P4MEDIUMCVSS 6.8v2.8v2.8.12014-03-25
CVE-2014-0885 [MEDIUM] CWE-352 CVE-2014-0885: Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
nvd
CVE-2016-2991P4MEDIUMCVSS 5.4v2.8v2.8.12016-12-01
CVE-2016-2991 [MEDIUM] CWE-79 CVE-2016-2991: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0884P4LOWCVSS 3.5v2.8v2.8.12014-03-25
CVE-2014-0884 [LOW] CWE-79 CVE-2014-0884: Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Securit Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
Ibm Lotus Protector For Mail Security vulnerabilities | cvebase