CVE-2012-5657

medium
Published 2013-05-02 · Modified 2024-12-04
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

Zend Framework XXE Vulnerability

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/51583

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://framework.zend.com/security/advisory/ZF2012-05

Package impact

EcosystemPackageVulnerableFixed
php Packagistzendframework/zendframework1<1.11.151.11.15
php Packagistzendframework/zendframework1>=1.12.0-rc1,<1.12.11.12.1

Application impact

VendorProductVersionsFixed
zendzend_framework1.11.0
zendzend_framework1.11.1
zendzend_framework1.11.2
zendzend_framework1.11.3
zendzend_framework1.11.4
zendzend_framework1.11.5
zendzend_framework1.11.6
zendzend_framework1.11.7
zendzend_framework1.11.8
zendzend_framework1.11.9
zendzend_framework1.11.10
zendzend_framework1.11.11
zendzend_framework1.11.12
zendzend_framework1.11.13
zendzend_framework1.12.0

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.