CVE-2012-4818
Summary
| CVE | CVE-2012-4818 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-29 03:15:00 UTC |
| Updated | 2022-10-28 22:39:00 UTC |
| Description | IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Infosphere Information Server | 8.1 | All | All | All |
| Application | Ibm | Infosphere Information Server | 8.5 | All | All | All |
| Application | Ibm | Infosphere Information Server | 8.7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cve-website | MISC | www.cve.org | |
| Security Bulletin: Lack of path restriction may allow access to sensitive data stored on IBM InfoSphere Information Server (CVE-2012-4818) - IBM PSIRT Blog | MISC | www.ibm.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.