peter bassill · operator
$ cve CVE-2012-0198 JSON

CVE-2012-0198 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 37.4% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS37.44% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2012-03-06
Last modified2026-06-16

Affected (1)

VendorProduct
ibmtivoli provisioning manager express for software distribution

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD