← Vulnerability feed

Vulnerability record · CVE-2012-2161 · published 20 June 2012

CVE-2012-2161: Ibm security appscan source cross-site scripting vulnerability

Ibm · Security Appscan Source

Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

4.3 CVSS 2.0 Medium EPSS 1.8% · top 22.7% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2161 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-6120Ibm rational appscan source command injection vulnerabilityIBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.…EPSS 5.0%9.3CVE-2014-6119Ibm security appscan code injection vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 3.6%9.3CVE-2012-0190Ibm spss data collection vulnerabilityUnspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Colle…EPSS 3.4%9.3CVE-2012-0188Ibm spss data collection vulnerabilityUnspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.…EPSS 3.4%7.2CVE-2014-3072Ibm security appscan source vulnerabilityUnspecified vulnerability in the Automation Server in IBM Security AppScan Source 8 through 8.0.0.2, 8.5 through 8.5.0.1, 8.6 through 8.6.0.2, 8.7 th…EPSS 0.37%5.8CVE-2012-2159Ibm security appscan source improper input validation vulnerabilityOpen redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collec…EPSS 1.8%5.5CVE-2014-6122Ibm security appscan permissions and access controls vulnerabilityIBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…EPSS 1.5%5.3CVE-2016-3035Ibm security appscan source information exposure vulnerabilityIBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2012-2161), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.