CVE-2012-0735

high
Published 2012-05-03 · Modified 2026-04-29
CVSS v3
CVSS v2
7.6
VIR risk
7.6

Description

IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly scan file: URLs, which allows man-in-the-middle attackers to obtain sensitive information or possibly have unspecified other impact via a crafted URI.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21592188

Application impact

VendorProductVersionsFixed
ibmrational_appscan5.2
ibmrational_appscan5.4
ibmrational_appscan5.5.0
ibmrational_appscan5.5.0.1
ibmrational_appscan5.5.0.2
ibmrational_appscan5.6.0
ibmrational_appscan5.6.0.3
ibmrational_appscan8.0.0
ibmrational_appscan8.0.0.1
ibmrational_appscan8.0.0.2
ibmrational_appscan8.0.0.3
ibmrational_appscan8.0.1
ibmrational_appscan8.0.1.1
ibmrational_appscan8.5.0
ibmrational_appscan8.5.0.0

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.