{
  "threat_severity" : "Moderate",
  "public_date" : "2012-07-19T00:00:00Z",
  "bugzilla" : {
    "description" : "System: multiple XSS flaws",
    "id" : "826646",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=826646"
  },
  "cvss" : {
    "cvss_base_score" : "4.3",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-79",
  "details" : [ "Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.", "Multiple cross-site scripting flaws were discovered in the Red Hat Certificate System Agent and End Entity pages. An attacker could use these flaws to perform a cross-site scripting (XSS) attack against victims using the Certificate System's web interface." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Certificate System 8",
    "release_date" : "2012-07-19T00:00:00Z",
    "advisory" : "RHSA-2012:1103",
    "cpe" : "cpe:/a:redhat:certificate_system:8::el5",
    "package" : "pki-common-0:8.1.1-1.el5pki"
  }, {
    "product_name" : "Red Hat Certificate System 8",
    "release_date" : "2012-07-19T00:00:00Z",
    "advisory" : "RHSA-2012:1103",
    "cpe" : "cpe:/a:redhat:certificate_system:8::el5",
    "package" : "pki-tps-0:8.1.1-1.el5pki"
  }, {
    "product_name" : "Red Hat Certificate System 8",
    "release_date" : "2012-07-19T00:00:00Z",
    "advisory" : "RHSA-2012:1103",
    "cpe" : "cpe:/a:redhat:certificate_system:8::el5",
    "package" : "pki-util-0:8.1.1-1.el5pki"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2015-07-20T00:00:00Z",
    "advisory" : "RHSA-2015:1347",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "pki-core-0:9.0.3-43.el6"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Will not fix",
    "package_name" : "pki-core",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2012-2662\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-2662" ],
  "name" : "CVE-2012-2662",
  "csaw" : false
}