Vulnerability Note VU#659791
IBM ISS Proventia Mail Security contains multiple vulnerabilities
Overview
IBM ISS Proventia Mail Security contains cross-site scripting and arbitrary file read vulnerabilities.
Description
The IBM security advisories state: CVE-2012-2955 Additional details may be found in the full advisories linked above. |
Impact
An attacker may be able to read arbitrary files or launch an XSS attack to steal cookies, execute scripts in the user's browser, etc. |
Solution
Apply an Update
- If automatic System Package Updates are enabled, no further action is necessary. The system will download and install the update automatically. - For manual System Package Updates: - Log in to the Management Console - Go to "Updates" -> "Updates & Licensing" - Install all pending System Package Updates Lotus Protector for Mail Security 2.5.x - Follow the instructions on http://www-01.ibm.com/support/docview.wss?uid=swg21605199 to download and install the fix. Lotus Protector for Mail Security 2.1.x - Upgrade to version 2.5.x or 2.8.x and follow the remediation steps listed above IBM Proventia Network Mail Security System 2.5.x and later - Follow the instructions on http://www-01.ibm.com/support/docview.wss?uid=swg21605199 to download and install the fix. IBM Proventia Network Mail Security System 2.4.x and earlier - Upgrade to version 2.5.x or later and follow the remediation steps listed above |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| IBM Corporation | Affected | 25 Jun 2012 | 25 Jul 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| Temporal | 3.6 | E:F/RL:OF/RC:C |
| Environmental | 3.6 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21605626
- http://www-01.ibm.com/support/docview.wss?uid=swg21605630
Credit
Thanks to Offensive Security for reporting these vulnerabilities.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2012-2955 CVE-2012-2202
- Date Public: 20 Jul 2012
- Date First Published: 25 Jul 2012
- Date Last Updated: 25 Jul 2012
- Document Revision: 16
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.