CVE-2012-0731

medium
Published 2012-05-03 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not prevent service-account impersonation, which allows remote authenticated users to read arbitrary files via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
ibmrational_appscan5.2
ibmrational_appscan5.4
ibmrational_appscan5.5.0
ibmrational_appscan5.5.0.1
ibmrational_appscan5.5.0.2
ibmrational_appscan5.6.0
ibmrational_appscan5.6.0.3
ibmrational_appscan8.0.0
ibmrational_appscan8.0.0.1
ibmrational_appscan8.0.0.2
ibmrational_appscan8.0.0.3
ibmrational_appscan8.0.1
ibmrational_appscan8.0.1.1
ibmrational_appscan8.5.0
ibmrational_appscan8.5.0.0

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.