{"api_version":"1","generated_at":"2026-07-23T06:49:34+00:00","cve":"CVE-2012-4612","urls":{"html":"https://cve.report/CVE-2012-4612","api":"https://cve.report/api/cve/CVE-2012-4612.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-4612","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-4612"},"summary":{"title":"CVE-2012-4612","description":"Cross-site scripting (XSS) vulnerability in EMC RSA Data Protection Manager Appliance and Software Server 2.7.x and 3.x before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"dell","published_at":"2012-11-16 00:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/56506","name":"http://www.securityfocus.com/bid/56506","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html","name":"http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-4612","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-4612","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"emc","cpe5":"rsa_data_protection_manager_appliance","cpe6":"2.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"emc","cpe5":"rsa_data_protection_manager_appliance","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"emc","cpe5":"rsa_data_protection_manager_appliance","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"emc","cpe5":"rsa_data_protection_manager_appliance","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"rsa_data_protection_manager_software_server","cpe6":"2.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"rsa_data_protection_manager_software_server","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"rsa_data_protection_manager_software_server","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"rsa_data_protection_manager_software_server","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T20:42:54.836Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"56506","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/56506"},{"name":"20121113 ESA-2012-055: RSA Data Protection Manager Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-11-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in EMC RSA Data Protection Manager Appliance and Software Server 2.7.x and 3.x before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-02-26T10:00:00.000Z","orgId":"c550e75a-17ff-4988-97f0-544cde3820fe","shortName":"dell"},"references":[{"name":"56506","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/56506"},{"name":"20121113 ESA-2012-055: RSA Data Protection Manager Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2012-4612","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in EMC RSA Data Protection Manager Appliance and Software Server 2.7.x and 3.x before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"56506","refsource":"BID","url":"http://www.securityfocus.com/bid/56506"},{"name":"20121113 ESA-2012-055: RSA Data Protection Manager Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html"}]}}}},"cveMetadata":{"assignerOrgId":"c550e75a-17ff-4988-97f0-544cde3820fe","assignerShortName":"dell","cveId":"CVE-2012-4612","datePublished":"2012-11-16T00:00:00.000Z","dateReserved":"2012-08-24T00:00:00.000Z","dateUpdated":"2024-08-06T20:42:54.836Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-16 00:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:emc:rsa_data_protection_manager_software_server:2.7.0:*:*:*:*:*:*:*","matchCriteriaId":"BD2D6AFF-90FB-4B40-88AE-16BEE0FBC281"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:rsa_data_protection_manager_software_server:3.0:*:*:*:*:*:*:*","matchCriteriaId":"A34EDF77-3FA7-43EF-B4D5-EE5C1849E766"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:rsa_data_protection_manager_software_server:3.1:*:*:*:*:*:*:*","matchCriteriaId":"B5F1498E-5272-46A6-9D94-41D7BAD8AEA0"},{"vulnerable":true,"criteria":"cpe:2.3:a:emc:rsa_data_protection_manager_software_server:3.2:*:*:*:*:*:*:*","matchCriteriaId":"BE9F0460-DAF6-409E-8D3A-EBCE70AB4C90"},{"vulnerable":true,"criteria":"cpe:2.3:h:emc:rsa_data_protection_manager_appliance:2.7.0:*:*:*:*:*:*:*","matchCriteriaId":"A4E90B05-EA3A-47B7-BF98-27DEC19740D8"},{"vulnerable":true,"criteria":"cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.0:*:*:*:*:*:*:*","matchCriteriaId":"24990883-A014-4E93-90A1-A36A52ACD967"},{"vulnerable":true,"criteria":"cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.1:*:*:*:*:*:*:*","matchCriteriaId":"FC03AD04-84EE-4FD1-A85F-FBC346364D36"},{"vulnerable":true,"criteria":"cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.2:*:*:*:*:*:*:*","matchCriteriaId":"1F178D3D-2CC7-4DAC-9059-53A472471954"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"4612","Ordinal":"1","Title":"CVE-2012-4612","CVE":"CVE-2012-4612","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"4612","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in EMC RSA Data Protection Manager Appliance and Software Server 2.7.x and 3.x before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2012-4612"},{"CveYear":"2012","CveId":"4612","Ordinal":"2","NoteData":"2012-11-15","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"4612","Ordinal":"3","NoteData":"2013-02-26","Type":"Other","Title":"Modified"}]}}}