Vulnerability Name: | CVE-2012-3301 (CCN-77400) | ||||||||
Assigned: | 2012-08-15 | ||||||||
Published: | 2012-08-15 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-disclosure Mailing List, Thu Sep 06 2012 HTTP Response Splitting and XSS vulnerabilities in IBM Lotus Domino Source: MITRE Type: CNA CVE-2012-3301 Source: CCN Type: SA50330 IBM Lotus Domino HTTP Response Splitting and Cross-Site Scripting Vulnerabilities Source: MISC Type: UNKNOWN http://websecurity.com.ua/5839/ Source: CCN Type: IBM Security Bulletin 1608160 Aug-2012 IBM Lotus Domino Web Server Cross-Site Scripting Vulnerabilities (CVE-2012-3302, CVE-2012-3301) Source: CONFIRM Type: UNKNOWN http://www-01.ibm.com/support/docview.wss?uid=swg21608160 Source: CCN Type: OSVDB ID: 84769 IBM Lotus Domino Unspecified HTTP Response Splitting Source: CCN Type: BID-55095 IBM Lotus Domino HTTP Response Splitting and Cross Site Scripting Vulnerabilities Source: XF Type: UNKNOWN lotus-domino-httpserver-response-splitting(77400) Source: XF Type: UNKNOWN lotus-domino-response-splitting(77400) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |