"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-08-11 13:01:36 +00:00
parent 95a2ee9bc5
commit 107614b75b
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
10 changed files with 456 additions and 196 deletions

View File

@ -106,6 +106,11 @@
"refsource": "CONFIRM",
"name": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-wifi-en",
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-wifi-en"
},
{
"refsource": "CONFIRM",
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-712518.pdf",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-712518.pdf"
}
]
}

View File

@ -4,14 +4,63 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-10777",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "secalert@redhat.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "CloudForms",
"version": {
"version_data": [
{
"version_value": "4.7 and 5"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Cross Site Scripting"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1847605",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1847605"
},
{
"refsource": "MISC",
"name": "https://access.redhat.com/security/cve/cve-2020-10777",
"url": "https://access.redhat.com/security/cve/cve-2020-10777"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms."
}
]
}

View File

@ -4,14 +4,63 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-10778",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "secalert@redhat.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "CloudForms",
"version": {
"version_data": [
{
"version_value": "4.7 and 5"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Incorrect Authorization"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1847628",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1847628"
},
{
"refsource": "MISC",
"name": "https://access.redhat.com/security/cve/cve-2020-10778",
"url": "https://access.redhat.com/security/cve/cve-2020-10778"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior."
}
]
}

View File

@ -4,14 +4,63 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-10779",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "secalert@redhat.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "CloudForms",
"version": {
"version_data": [
{
"version_value": "4.7 and 5"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper Access Control"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1847647",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1847647"
},
{
"refsource": "MISC",
"name": "https://access.redhat.com/security/cve/cve-2020-10779",
"url": "https://access.redhat.com/security/cve/cve-2020-10779"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms."
}
]
}

View File

@ -4,14 +4,63 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-10783",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "secalert@redhat.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "CloudForms",
"version": {
"version_data": [
{
"version_value": "4.7 and 5"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper Access Control"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1847811",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1847811"
},
{
"refsource": "MISC",
"name": "https://access.redhat.com/security/cve/cve-2020-10783",
"url": "https://access.redhat.com/security/cve/cve-2020-10783"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importing administrator files."
}
]
}

View File

@ -34,7 +34,7 @@
"description_data": [
{
"lang": "eng",
"value": "In IJG JPEG (aka libjpeg) before 9d, jdhuff.c has an out-of-bounds array read for certain table pointers."
"value": "In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers."
}
]
},
@ -61,6 +61,11 @@
"url": "http://www.ijg.org/files/jpegsrc.v9d.tar.gz",
"refsource": "MISC",
"name": "http://www.ijg.org/files/jpegsrc.v9d.tar.gz"
},
{
"refsource": "MISC",
"name": "https://github.com/libjpeg-turbo/libjpeg-turbo/issues/445",
"url": "https://github.com/libjpeg-turbo/libjpeg-turbo/issues/445"
}
]
}

View File

@ -4,14 +4,63 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-14325",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "secalert@redhat.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "CloudForms",
"version": {
"version_data": [
{
"version_value": "cfme 5.11.7.0"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper Authorization"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1855739",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1855739"
},
{
"refsource": "MISC",
"name": "https://access.redhat.com/security/cve/cve-2020-14325",
"url": "https://access.redhat.com/security/cve/cve-2020-14325"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator."
}
]
}

View File

@ -1,93 +1,93 @@
{
"data_version" : "4.0",
"references" : {
"reference_data" : [
{
"name" : "https://www.ibm.com/support/pages/node/6257885",
"title" : "IBM Security Bulletin 6257885 (QRadar Wincollect)",
"refsource" : "CONFIRM",
"url" : "https://www.ibm.com/support/pages/node/6257885"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/181860",
"name" : "ibm-qradar-cve20204485-dos (181860)",
"title" : "X-Force Vulnerability Report",
"refsource" : "XF"
}
]
},
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security mechanisms in future attacks. IBM X-Force ID: 181860."
}
]
},
"data_format" : "MITRE",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Denial of Service",
"lang" : "eng"
}
]
}
]
},
"data_type" : "CVE",
"affects" : {
"vendor" : {
"vendor_data" : [
"data_version": "4.0",
"references": {
"reference_data": [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"product_name" : "QRadar Wincollect",
"version" : {
"version_data" : [
{
"version_value" : "7.2.0"
},
{
"version_value" : "7.2.9"
}
]
}
}
]
}
"name": "https://www.ibm.com/support/pages/node/6257885",
"title": "IBM Security Bulletin 6257885 (QRadar Wincollect)",
"refsource": "CONFIRM",
"url": "https://www.ibm.com/support/pages/node/6257885"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/181860",
"name": "ibm-qradar-cve20204485-dos (181860)",
"title": "X-Force Vulnerability Report",
"refsource": "XF"
}
]
}
},
"CVE_data_meta" : {
"DATE_PUBLIC" : "2020-08-10T00:00:00",
"ID" : "CVE-2020-4485",
"ASSIGNER" : "psirt@us.ibm.com",
"STATE" : "PUBLIC"
},
"impact" : {
"cvssv3" : {
"TM" : {
"RC" : "C",
"RL" : "O",
"E" : "U"
},
"BM" : {
"S" : "U",
"I" : "N",
"A" : "H",
"SCORE" : "6.500",
"AC" : "L",
"C" : "N",
"AV" : "N",
"UI" : "N",
"PR" : "L"
}
}
}
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "IBM QRadar 7.2.0 through 7.2.9 could allow an authenticated user to disable the Wincollect service which could aid an attacker in bypassing security mechanisms in future attacks. IBM X-Force ID: 181860."
}
]
},
"data_format": "MITRE",
"problemtype": {
"problemtype_data": [
{
"description": [
{
"value": "Denial of Service",
"lang": "eng"
}
]
}
]
},
"data_type": "CVE",
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "IBM",
"product": {
"product_data": [
{
"product_name": "QRadar Wincollect",
"version": {
"version_data": [
{
"version_value": "7.2.0"
},
{
"version_value": "7.2.9"
}
]
}
}
]
}
}
]
}
},
"CVE_data_meta": {
"DATE_PUBLIC": "2020-08-10T00:00:00",
"ID": "CVE-2020-4485",
"ASSIGNER": "psirt@us.ibm.com",
"STATE": "PUBLIC"
},
"impact": {
"cvssv3": {
"TM": {
"RC": "C",
"RL": "O",
"E": "U"
},
"BM": {
"S": "U",
"I": "N",
"A": "H",
"SCORE": "6.500",
"AC": "L",
"C": "N",
"AV": "N",
"UI": "N",
"PR": "L"
}
}
}
}

View File

@ -1,93 +1,93 @@
{
"impact" : {
"cvssv3" : {
"BM" : {
"A" : "H",
"I" : "H",
"S" : "U",
"PR" : "L",
"UI" : "N",
"AV" : "N",
"SCORE" : "8.100",
"C" : "N",
"AC" : "L"
},
"TM" : {
"RC" : "C",
"RL" : "O",
"E" : "U"
}
}
},
"data_type" : "CVE",
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"product_name" : "QRadar Wincollect",
"version" : {
"version_data" : [
{
"version_value" : "7.2.0"
},
{
"version_value" : "7.2.9"
}
]
}
}
]
}
"impact": {
"cvssv3": {
"BM": {
"A": "H",
"I": "H",
"S": "U",
"PR": "L",
"UI": "N",
"AV": "N",
"SCORE": "8.100",
"C": "N",
"AC": "L"
},
"TM": {
"RC": "C",
"RL": "O",
"E": "U"
}
]
}
},
"CVE_data_meta" : {
"DATE_PUBLIC" : "2020-08-10T00:00:00",
"STATE" : "PUBLIC",
"ID" : "CVE-2020-4486",
"ASSIGNER" : "psirt@us.ibm.com"
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "File Manipulation"
}
}
},
"data_type": "CVE",
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "IBM",
"product": {
"product_data": [
{
"product_name": "QRadar Wincollect",
"version": {
"version_data": [
{
"version_value": "7.2.0"
},
{
"version_value": "7.2.9"
}
]
}
}
]
}
}
]
}
]
},
"data_format" : "MITRE",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. IBM X-Force ID: 181861."
}
]
},
"references" : {
"reference_data" : [
{
"refsource" : "CONFIRM",
"name" : "https://www.ibm.com/support/pages/node/6257885",
"title" : "IBM Security Bulletin 6257885 (QRadar Wincollect)",
"url" : "https://www.ibm.com/support/pages/node/6257885"
},
{
"refsource" : "XF",
"name" : "ibm-qradar-cve20204486-file-delete (181861)",
"title" : "X-Force Vulnerability Report",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/181861"
}
]
},
"data_version" : "4.0"
}
}
},
"CVE_data_meta": {
"DATE_PUBLIC": "2020-08-10T00:00:00",
"STATE": "PUBLIC",
"ID": "CVE-2020-4486",
"ASSIGNER": "psirt@us.ibm.com"
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "File Manipulation"
}
]
}
]
},
"data_format": "MITRE",
"description": {
"description_data": [
{
"lang": "eng",
"value": "IBM QRadar 7.2.0 thorugh 7.2.9 could allow an authenticated user to overwrite or delete arbitrary files due to a flaw after WinCollect installation. IBM X-Force ID: 181861."
}
]
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"name": "https://www.ibm.com/support/pages/node/6257885",
"title": "IBM Security Bulletin 6257885 (QRadar Wincollect)",
"url": "https://www.ibm.com/support/pages/node/6257885"
},
{
"refsource": "XF",
"name": "ibm-qradar-cve20204486-file-delete (181861)",
"title": "X-Force Vulnerability Report",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/181861"
}
]
},
"data_version": "4.0"
}

View File

@ -151,6 +151,11 @@
"refsource": "CONFIRM",
"name": "https://kb.netgear.com/000061806/Security-Advisory-for-Unauthenticated-Remote-Buffer-Overflow-Attack-in-PPPD-on-WAC510-PSV-2020-0136",
"url": "https://kb.netgear.com/000061806/Security-Advisory-for-Unauthenticated-Remote-Buffer-Overflow-Attack-in-PPPD-on-WAC510-PSV-2020-0136"
},
{
"refsource": "MISC",
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-809841.pdf",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-809841.pdf"
}
]
}