{"api_version":"1","generated_at":"2026-07-23T11:27:55+00:00","cve":"CVE-2012-2455","urls":{"html":"https://cve.report/CVE-2012-2455","api":"https://cve.report/api/cve/CVE-2012-2455.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2455","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2455"},"summary":{"title":"CVE-2012-2455","description":"Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-11-10 00:55:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/85499","name":"http://www.osvdb.org/85499","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://seclists.org/fulldisclosure/2012/Sep/62","name":"http://seclists.org/fulldisclosure/2012/Sep/62","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Full Disclosure: Authentication flaw in APS-Soft DTE Axiom\t(CVE-2012-2455)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/50508","name":"http://secunia.com/advisories/50508","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA50508 - DTE Axiom Registration ID Verification Security Bypass - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2455","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2455","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2455","vulnerable":"1","versionEndIncluding":"12.3.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"advance_productivity_software","cpe5":"dte_axiom","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:34:25.696Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20120906 Authentication flaw in APS-Soft DTE Axiom (CVE-2012-2455)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2012/Sep/62"},{"name":"50508","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/50508"},{"name":"85499","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/85499"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-11-10T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20120906 Authentication flaw in APS-Soft DTE Axiom (CVE-2012-2455)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2012/Sep/62"},{"name":"50508","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/50508"},{"name":"85499","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/85499"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-2455","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20120906 Authentication flaw in APS-Soft DTE Axiom (CVE-2012-2455)","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2012/Sep/62"},{"name":"50508","refsource":"SECUNIA","url":"http://secunia.com/advisories/50508"},{"name":"85499","refsource":"OSVDB","url":"http://www.osvdb.org/85499"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-2455","datePublished":"2012-11-10T00:00:00.000Z","dateReserved":"2012-05-04T00:00:00.000Z","dateUpdated":"2024-09-16T17:49:29.867Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-10 00:55:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:advance_productivity_software:dte_axiom:*:*:*:*:*:*:*:*","versionEndIncluding":"12.3.2","matchCriteriaId":"A34C5A8F-A434-49CD-AEC1-B40781C58A9E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2455","Ordinal":"1","Title":"CVE-2012-2455","CVE":"CVE-2012-2455","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2455","Ordinal":"1","NoteData":"Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication and read or modify data about users, customers, and projects via unspecified vectors.","Type":"Description","Title":"CVE-2012-2455"},{"CveYear":"2012","CveId":"2455","Ordinal":"2","NoteData":"2012-11-09","Type":"Other","Title":"Published"}]}}}