CVE-2012-3301

Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
ibmlotus_domino
8.5.0
ibmlotus_domino
8.5.0.1
ibmlotus_domino
8.5.1.1
ibmlotus_domino
8.5.1.2
ibmlotus_domino
8.5.1.3
ibmlotus_domino
8.5.1.4
ibmlotus_domino
8.5.1.5
ibmlotus_domino
8.5.2.0
ibmlotus_domino
8.5.2.1
ibmlotus_domino
8.5.2.2
ibmlotus_domino
8.5.2.3
ibmlotus_domino
8.5.2.4
ibmlotus_domino
8.5.3.0
ibmlotus_domino
8.5.3.1
ibmlotus_domino
8.5.3.2
𝑥
= Vulnerable software versions