CVE-2012-4825: IBM Lotus Notes Traveler

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in servlet/traveler/ILNT.mobileconfig in IBM Lotus Notes Traveler before 8.5.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) userId or (2) address parameter in a getClientConfigFile action.

Affected products

  • IBM Lotus Notes Traveler: up to and including 8.5.3.1; version 8.5.0.0 only; version 8.5.0.1 only; version 8.5.0.2 only; version 8.5.1.1 only; version 8.5.1.2 only; …

Published 2012-10-08. Last modified 2026-06-16.