← Vulnerability feed

Vulnerability record · CVE-2012-2159 · published 20 June 2012

CVE-2012-2159: Ibm security appscan source improper input validation vulnerability

Ibm · Security Appscan Source

Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

5.8 CVSS 2.0 Medium EPSS 1.8% · top 21.8% CWE-20 · Improper input validation
5.8CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2159 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-6120Ibm rational appscan source command injection vulnerabilityIBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…EPSS 5.0%9.3CVE-2014-6119Ibm security appscan code injection vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 3.6%9.3CVE-2012-0190Ibm spss data collection vulnerabilityUnspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Colle…EPSS 3.4%9.3CVE-2012-0188Ibm spss data collection vulnerabilityUnspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.…EPSS 3.4%7.2CVE-2014-3072Ibm security appscan source vulnerabilityUnspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 th…EPSS 0.37%5.5CVE-2014-6122Ibm security appscan permissions and access controls vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 1.5%5.3CVE-2016-3035Ibm security appscan source information exposure vulnerabilityIBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.EPSS 1.0%5.0CVE-2012-2173Ibm security appscan source vulnerabilityThe ODBC driver in IBM Security AppScan Source 7.x and 8.x before 8.6 sends an SHA-1 hash of the connection password during connections to a solidDB …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2012-2159), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.