cvelist/2018/1xxx/CVE-2018-1668.json

109 lines
3.7 KiB
JSON
Raw Normal View History

2017-12-13 17:04:27 -05:00
{
2019-03-17 21:29:37 +00:00
"CVE_data_meta": {
"ASSIGNER": "psirt@us.ibm.com",
"DATE_PUBLIC": "2019-01-11T00:00:00",
"ID": "CVE-2018-1668",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "DataPower Gateway",
"version": {
"version_data": [
{
"version_value": "7.6.0.0"
},
{
"version_value": "7.5.2.0"
},
{
"version_value": "7.5.1.0"
},
{
"version_value": "7.5.0.0"
},
{
"version_value": "7.5.0.19"
},
{
"version_value": "7.5.1.18"
},
{
"version_value": "7.5.2.18"
},
{
"version_value": "7.6.0.11"
}
]
}
}
]
},
"vendor_name": "IBM"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
2019-03-17 21:29:37 +00:00
"lang": "eng",
"value": "IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows \"null\" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894."
}
2019-03-17 21:29:37 +00:00
]
},
"impact": {
"cvssv3": {
"BM": {
"A": "N",
"AC": "L",
"AV": "N",
"C": "L",
"I": "N",
"PR": "N",
"S": "U",
"SCORE": "5.300",
"UI": "N"
},
"TM": {
"E": "U",
"RC": "C",
"RL": "O"
}
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Obtain Information"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "ibm-websphere-cve20181668-info-disc(144894)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/144894"
},
{
"name": "https://www.ibm.com/support/docview.wss?uid=ibm10794735",
"refsource": "CONFIRM",
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10794735"
}
]
}
}