cvelist/2020/5xxx/CVE-2020-5331.json

72 lines
2.5 KiB
JSON
Raw Normal View History

2020-01-03 14:01:42 +00:00
{
"CVE_data_meta": {
2020-05-04 19:01:28 +00:00
"ASSIGNER": "secure@dell.com",
"DATE_PUBLIC": "2020-02-28",
"ID": "CVE-2020-5331",
"STATE": "PUBLIC"
2020-05-04 19:01:28 +00:00
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
2020-05-04 19:01:28 +00:00
"product_name": "RSA Archer",
"version": {
"version_data": [
{
2020-05-04 19:01:28 +00:00
"version_affected": "<",
"version_value": "6.7 P3"
}
]
}
}
]
2020-05-04 19:01:28 +00:00
},
"vendor_name": "Dell"
}
]
}
2020-05-04 19:01:28 +00:00
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2020-01-03 14:01:42 +00:00
"description": {
"description_data": [
{
2020-05-04 19:01:28 +00:00
"lang": "eng",
"value": "RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users\u2019 session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks."
}
]
2020-05-04 19:01:28 +00:00
},
"impact": {
"cvss": {
2020-05-04 19:01:28 +00:00
"baseScore": 8.8,
"baseSeverity": "High",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
2020-05-04 19:01:28 +00:00
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
2020-05-04 19:01:28 +00:00
"lang": "eng",
"value": "CWE-598: Information Exposure Through Query Strings in GET Request"
}
]
}
]
2020-05-04 19:01:28 +00:00
},
"references": {
"reference_data": [
{
2020-05-04 19:01:28 +00:00
"refsource": "MISC",
"url": "https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities",
"name": "https://www.dell.com/support/security/en-us/details/DOC-111112/DSA-2020-049-RSA-Archer-Security-Update-for-Multiple-Vulnerabilities"
2020-01-03 14:01:42 +00:00
}
]
}
}