{"api_version":"1","generated_at":"2026-07-23T05:38:19+00:00","cve":"CVE-2012-1291","urls":{"html":"https://cve.report/CVE-2012-1291","api":"https://cve.report/api/cve/CVE-2012-1291.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-1291","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-1291"},"summary":{"title":"CVE-2012-1291","description":"Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-02-23 20:07:25","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://dsecrg.com/pages/vul/show.php?id=415","name":"http://dsecrg.com/pages/vul/show.php?id=415","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Digital Security Research Group - [DSECRG-12-015] SAP Adapter Monitor - information disclosure","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/47861","name":"http://secunia.com/advisories/47861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a","name":"http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Acknowledgments to Security Researchers | SCN","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/52101","name":"http://www.securityfocus.com/bid/52101","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SAP NetWeaver Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://service.sap.com/sap/support/notes/1585527","name":"https://service.sap.com/sap/support/notes/1585527","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-1291","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1291","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"1291","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"netweaver","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:53:37.020Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"52101","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/52101"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://dsecrg.com/pages/vul/show.php?id=415"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://service.sap.com/sap/support/notes/1585527"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a"},{"name":"47861","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47861"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-02-23T18:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"52101","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/52101"},{"tags":["x_refsource_MISC"],"url":"http://dsecrg.com/pages/vul/show.php?id=415"},{"tags":["x_refsource_MISC"],"url":"https://service.sap.com/sap/support/notes/1585527"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a"},{"name":"47861","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47861"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-1291","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"52101","refsource":"BID","url":"http://www.securityfocus.com/bid/52101"},{"name":"http://dsecrg.com/pages/vul/show.php?id=415","refsource":"MISC","url":"http://dsecrg.com/pages/vul/show.php?id=415"},{"name":"https://service.sap.com/sap/support/notes/1585527","refsource":"MISC","url":"https://service.sap.com/sap/support/notes/1585527"},{"name":"http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a","refsource":"CONFIRM","url":"http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a"},{"name":"47861","refsource":"SECUNIA","url":"http://secunia.com/advisories/47861"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-1291","datePublished":"2012-02-23T18:00:00.000Z","dateReserved":"2012-02-23T00:00:00.000Z","dateUpdated":"2024-09-16T22:46:13.378Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-02-23 20:07:25","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:netweaver:7.0:*:*:*:*:*:*:*","matchCriteriaId":"41FAC5DD-D577-47F9-B0CA-006032256642"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"1291","Ordinal":"1","Title":"CVE-2012-1291","CVE":"CVE-2012-1291","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"1291","Ordinal":"1","NoteData":"Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service.","Type":"Description","Title":"CVE-2012-1291"},{"CveYear":"2012","CveId":"1291","Ordinal":"2","NoteData":"2012-02-23","Type":"Other","Title":"Published"}]}}}