CVE-2012-2997
Published Jan 21, 2014
Last updated 7 years ago
Overview
- Description
- XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file.
- Source
- cret@cert.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:f5:big-ip_configuration_utility:10.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BA56D52-2B65-46E3-832F-19D50C18178E" }, { "criteria": "cpe:2.3:a:f5:big-ip_configuration_utility:10.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C46C9AE-EBD1-4CAD-8C5C-2BD6B4816455" }, { "criteria": "cpe:2.3:a:f5:big-ip_configuration_utility:11.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F477AA97-6352-4738-A25E-AB270CC05B07" }, { "criteria": "cpe:2.3:a:f5:big-ip_configuration_utility:11.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1356BA4-B1A6-464D-A83E-EF3F584CA691" } ], "operator": "OR" } ] } ]