CVE-2012-4856
UnknownEPSS 1.17%
Last modified
CVE-2012-4856 is a vulnerability of currently unknown severity. The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Power 5 System Firmware | <= sf240_418 |
| Ibm | Power 5 System Firmware | sf240_201_201 |
| Ibm | Power 5 System Firmware | sf240_202_201 |
| Ibm | Power 5 System Firmware | sf240_219_201 |
| Ibm | Power 5 System Firmware | sf240_222_201 |
| Ibm | Power 5 System Firmware | sf240_233_201 |
| Ibm | Power 5 System Firmware | sf240_258_201 |
| Ibm | Power 5 System Firmware | sf240_259_201 |
| Ibm | Power 5 System Firmware | sf240_261_201 |
| Ibm | Power 5 System Firmware | sf240_284_201 |
| Ibm | Power 5 System Firmware | sf240_298_201 |
| Ibm | Power 5 System Firmware | sf240_299_201 |
| Ibm | Power 5 System Firmware | sf240_320_201 |
| Ibm | Power 5 System Firmware | sf240_332_201 |
| Ibm | Power 5 System Firmware | sf240_338_201 |
| Ibm | Power 5 System Firmware | sf240_358_201 |
| Ibm | Power 5 System Firmware | sf240_371 |
| Ibm | Power 5 System Firmware | sf240_382_382 |
| Ibm | Power 5 System Firmware | sf240_403_382 |
| Ibm | Power 5 System Firmware | sf240_415_382 |
| Ibm | Power 5 System Firmware | sf240_417 |
| Ibm | Power 5 | 9110-51a |
| Ibm | Power 5 | 9110-510 |
| Ibm | Power 5 | 9111-285 |
| Ibm | Power 5 | 9111-520 |
| Ibm | Power 5 | 9113-550 |
| Ibm | Power 5 | 9115-505 |
| Ibm | Power 5 | 9116-561 |
| Ibm | Power 5 | 9117-570 |
| Ibm | Power 5 | 9118-575 |
| Ibm | Power 5 | 9123-710 |
| Ibm | Power 5 | 9124-720 |
| Ibm | Power 5 | 9131-52a |
| Ibm | Power 5 | 9133-55a |
| Ibm | Power 5 | 9405-520 |
| Ibm | Power 5 | 9406-520 |
| Ibm | Power 5 | 9406-525 |
| Ibm | Power 5 | 9406-550 |
| Ibm | Power 5 | 9406-570 |
| Ibm | Power 5 | 9407-515 |
References
- http://www.kb.cert.org/vuls/id/194604US Government Resource
- http://www.kb.cert.org/vuls/id/194604US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4856?
The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.
How severe is CVE-2012-4856?
Severity scoring for CVE-2012-4856 is pending analysis. The EPSS model estimates a 1.17% probability of exploitation in the next 30 days.
How do I fix CVE-2012-4856?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-4847IBM Cognos Business Intelligence (BI) 8.4 and 8.4.1 allows r…
- CVE-2012-4848Multiple cross-site scripting (XSS) vulnerabilities in IBM L…
- CVE-2012-4850IBM WebSphere Application Server 8.5 Liberty Profile before …
- CVE-2012-4851Cross-site scripting (XSS) vulnerability in IBM WebSphere Ap…
- CVE-2012-4853Cross-site request forgery (CSRF) vulnerability in IBM WebSp…
- CVE-2012-4855Unspecified vulnerability in the web services framework in I…
- CVE-2012-4857Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 an…
- CVE-2012-4858IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1…
- CVE-2012-4859Unspecified vulnerability in IBM Tivoli Storage Manager for …
- CVE-2012-4861The web server in InfoSphere Data Replication Dashboard in I…
- CVE-2012-4862The Host Connect emulator in IBM Rational Developer for Syst…
- CVE-2012-4863IBM WebSphere MQ 7.1 and 7.5: Queue manager has a DoS vulner…6.5
Are you affected by CVE-2012-4856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
