CVE-2012-2552

UnknownEPSS 16.30%

Last modified

CVE-2012-2552 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability.". EPSS estimates a 16.30% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."

Metrics

EPSS Probability
16.30%

96.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
MicrosoftSql Server2005Sp4
MicrosoftSql Server2008R2 Sp1
MicrosoftSql Server2012
MicrosoftSql Server Reporting Services2000Sp2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-2552?
Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
How severe is CVE-2012-2552?
Severity scoring for CVE-2012-2552 is pending analysis. The EPSS model estimates a 16.30% probability of exploitation in the next 30 days.
How do I fix CVE-2012-2552?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-2552?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST