2024-12-08 03:06:42 +00:00

107 lines
3.0 KiB
JSON

{
"id": "CVE-2012-2455",
"sourceIdentifier": "cve@mitre.org",
"published": "2012-11-10T00:55:03.257",
"lastModified": "2024-11-21T01:39:08.000",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors."
},
{
"lang": "es",
"value": "Advanced Software Productividad Axiom DTE antes de v12.3.3 no valida la ID de registro, lo que permite a atacantes remotos evitar la autenticaci\u00f3n y leer o modificar datos de los usuarios, clientes y proyectos a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"baseScore": 6.4,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:advance_productivity_software:dte_axiom:*:*:*:*:*:*:*:*",
"versionEndIncluding": "12.3.2",
"matchCriteriaId": "A34C5A8F-A434-49CD-AEC1-B40781C58A9E"
}
]
}
]
}
],
"references": [
{
"url": "http://seclists.org/fulldisclosure/2012/Sep/62",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/50508",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.osvdb.org/85499",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2012/Sep/62",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/50508",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.osvdb.org/85499",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}