peter bassill · operator
$ cve CVE-2012-2172 JSON

CVE-2012-2172 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote attackers to inject arbitrary web script or HTML via the updateRegn parameter.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.63% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2012-06-22
Last modified2026-06-16

Affected (18)

VendorProduct
ibmds storage manager host software
ibmds4100
ibmds4200
ibmds4300
ibmds4400
ibmds4500
ibmds4700
ibmds4800
ibmsystem storage dcs3700 storage subsystem
ibmsystem storage ds3200
ibmsystem storage ds3300
ibmsystem storage ds3400
ibmsystem storage ds3512
ibmsystem storage ds3524
ibmsystem storage ds3950 express
ibmsystem storage ds5020 disk controller
ibmsystem storage ds5100 storage controller
ibmsystem storage ds5300 storage controller

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD