CVE-2012-0191
IBM Lotus Expeditor 6.1.x and 6.2.x - Unauthenticated Request Spoofing via Crafted Headers
Title source: llmDescription
The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21575642
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72156
Scores
EPSS
0.0103
EPSS Percentile
60.3%
Details
CWE
CWE-264
Status
published
Products (6)
ibm/lotus_expeditor
6.1
ibm/lotus_expeditor
6.1.1
ibm/lotus_expeditor
6.2
ibm/lotus_expeditor
6.2.1
ibm/lotus_expeditor
6.2.2
ibm/lotus_expeditor
6.2.3
Published
Jun 22, 2012
Tracked Since
Feb 18, 2026