CVE-2012-2684
Summary
| CVE | CVE-2012-2684 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-28 17:55:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Mrg | 2.0 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.3160-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4369-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4410-2 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4494-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4794-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4916-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5033-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5037-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5054-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5068-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5092-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5098-2 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5105-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-2 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-3 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-4 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-5 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5192-1 | All | All | All |
| Application | Trevor Mckay | Cumin | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 17 Update: cumin-0.1.5522-4.fc17 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| 830245 – (CVE-2012-2684) CVE-2012-2684 cumin: SQL injection flaw | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 16 Update: cumin-0.1.5522-4.fc16 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.