CVE-2012-2203
Summary
| CVE | CVE-2012-2203 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-08 10:26:18 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Global Security Kit | 7.0.4.28 | All | All | All |
| Application | Ibm | Global Security Kit | 7.0.4.29 | All | All | All |
| Application | Ibm | Global Security Kit | All | All | All | All |
| Application | Ibm | Rational Directory Server | All | All | All | All |
| Application | Ibm | Tivoli Directory Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IV31973: SYSROUTE OF IV31970:GSKIT TRUST ANCHOR VULNERABILITY IN TIVOLI ACCESS MANAGER FOR E-BUSINESS (CVE-2012-2203) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Security Bulletin: Multiple vulnerabilities in Rational Directory Server (CVE-2012-2203, CVE-2012-2191) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM Multiple Products Global Security Toolkit Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IV31975: SYSROUTE OF IV31975:GSKIT TRUST ANCHOR VULNERABILITY IN TIVOLI ACCESS MANAGER FOR E-BUSINESS (CVE-2012-2203) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisory SA51279 - IBM Tivoli Access Manager for e-business GSKIT Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.