CVE-2012-0705
Summary
| CVE | CVE-2012-0705 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-01-31 12:06:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Infosphere Information Server | 8.1 | All | All | All |
| Application | Ibm | Infosphere Information Server | 8.5 | All | All | All |
| Application | Ibm | Infosphere Information Server | 8.5.0.1 | All | All | All |
| Application | Ibm | Infosphere Information Server | 8.5.0.2 | All | All | All |
| Application | Ibm | Infosphere Information Server | 8.7 | All | All | All |
| Application | Ibm | Infosphere Information Server | 9.1 | All | All | All |
| Application | Ibm | Infosphere Information Server Metabrokers Bridges | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM Security Bulletin: Multiple security vulnerabilities in the IBM InfoSphere Information Server Suite. - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.