VYPR

Lotus Expeditor

by IBM

CVEs (3)

  • CVE-2012-0191Jun 22, 2012
    risk 0.00cvss epss 0.00

    The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers.

  • CVE-2012-0187Jun 22, 2012
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.

  • CVE-2012-0186Jun 22, 2012
    risk 0.00cvss epss 0.00

    Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL.