CVE-2012-2965
Caucho Quercus, as distributed in Resin, does not properly handle unspecified characters in the names of variables
EPSS 1.5%
Description
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.
How to fix CVE-2012-2965
To remediate CVE-2012-2965, upgrade the affected package to a fixed version below.
- Maven/com.caucho:resin—upgrade to 4.0.29 or later
Is CVE-2012-2965 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.0.29
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U |