2024-12-08 03:06:42 +00:00

92 lines
2.9 KiB
JSON

{
"id": "CVE-2012-0198",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2012-03-06T04:18:03.063",
"lastModified": "2024-11-21T01:34:33.780",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file."
},
{
"lang": "es",
"value": "Desbordamiento de b\u00fafer basado en pila en el m\u00e9todo RunAndUploadFile en el control Isig.isigCtl.1 ActiveXl en IBM Tivoli Provisioning Manager Express para distribuci\u00f3n de software v4.1.1, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de vectores relacionados con el fichero de informaci\u00f3n Asset."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"baseScore": 9.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:tivoli_provisioning_manager_express_for_software_distribution:4.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "3A039B9D-4EFA-44FD-8986-2BE0FFB0C5E0"
}
]
}
]
}
],
"references": [
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-12-040/",
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73033",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-12-040/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73033",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}