CVE-2012-3301

EUVD-2012-3279
Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
ibmlotus_domino
8.5.0
ibmlotus_domino
8.5.0.1
ibmlotus_domino
8.5.1.1
ibmlotus_domino
8.5.1.2
ibmlotus_domino
8.5.1.3
ibmlotus_domino
8.5.1.4
ibmlotus_domino
8.5.1.5
ibmlotus_domino
8.5.2.0
ibmlotus_domino
8.5.2.1
ibmlotus_domino
8.5.2.2
ibmlotus_domino
8.5.2.3
ibmlotus_domino
8.5.2.4
ibmlotus_domino
8.5.3.0
ibmlotus_domino
8.5.3.1
ibmlotus_domino
8.5.3.2
𝑥
= Vulnerable software versions