CVE-2012-5607

EUVD-2012-5493
The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 4.0.8
owncloudowncloud_server
3.0.0
owncloudowncloud_server
3.0.1
owncloudowncloud_server
3.0.2
owncloudowncloud_server
3.0.3
owncloudowncloud_server
4.0.0
owncloudowncloud_server
4.0.1
owncloudowncloud_server
4.0.2
owncloudowncloud_server
4.0.3
owncloudowncloud_server
4.0.4
owncloudowncloud_server
4.0.5
owncloudowncloud_server
4.0.6
owncloudowncloud_server
4.0.7
owncloudowncloud_server
4.5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
hardy
dne
lucid
dne
oneiric
ignored
precise
not-affected
quantal
Fixed 4.0.8debian-1.1ubuntu0.1
released
raring
not-affected
saucy
not-affected
trusty
dne
utopic
dne
vivid
dne
wily
dne
Common Weakness Enumeration