CVE-2012-2202 describes a directory traversal vulnerability in IBM Lotus Protector for Mail Security and IBM ISS Proventia Network Mail Security System. This flaw allows remote authenticated administrators to read arbitrary files by manipulating the 'template' parameter in javatester_init.php. The vulnerability has a CVSS score of 3.5, indicating a medium attack complexity and partial confidentiality impact, but no integrity or availability impact. While not listed in CISA's KEV catalog, public exploit code exists, and it has a FAUCET Risk Score of 75/100, though it lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1CPE matchmatch criteria | cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.1:*:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.5:*:*:*:*:*:*:* | ||
2.5.1CPE matchmatch criteria | cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.5.1:*:*:*:*:*:*:* | ||
2.8CPE matchmatch criteria | cpe:2.3:a:ibm:lotus_protector_for_mail_security:2.8:*:*:*:*:*:*:* | ||
2.5CPE matchmatch criteria | cpe:2.3:o:ibm:proventia_network_mail_security_system_firmware:2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.