SB2012081613 - Multiple vulnerabilities in Fortify Software Security Center



SB2012081613 - Multiple vulnerabilities in Fortify Software Security Center

Published: August 16, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012081613
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2012-3249)

The vulnerability allows a remote #AU# to gain access to sensitive information.

HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.


2) Information disclosure (CVE-ID: CVE-2012-3248)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote attackers to obtain sensitive information via unspecified vectors.


Remediation

Install update from vendor's website.