Merge branch 'IBM20181211-10177' of https://github.com/ScottMooreIBM/cvelist

This commit is contained in:
CVE Team 2018-12-11 10:40:53 -05:00
commit 187fcc4066
No known key found for this signature in database
GPG Key ID: 0DA1F9F56BC892E8
4 changed files with 409 additions and 30 deletions

View File

@ -1,18 +1,148 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1652",
"STATE" : "RESERVED"
"impact" : {
"cvssv3" : {
"BM" : {
"AC" : "L",
"A" : "H",
"AV" : "L",
"PR" : "N",
"C" : "N",
"SCORE" : "6.200",
"UI" : "N",
"S" : "U",
"I" : "N"
},
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "U"
}
}
},
"CVE_data_meta" : {
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2018-12-10T00:00:00",
"ID" : "CVE-2018-1652",
"STATE" : "PUBLIC"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.",
"lang" : "eng"
}
]
},
"data_version" : "4.0",
"references" : {
"reference_data" : [
{
"title" : "IBM Security Bulletin 744557 (DataPower Gateways)",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10744557",
"refsource" : "CONFIRM",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10744557"
},
{
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10717483",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10717483",
"refsource" : "CONFIRM",
"title" : "IBM Security Bulletin 717483 (MQ Appliance)"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/144724",
"title" : "X-Force Vulnerability Report",
"refsource" : "XF",
"name" : "ibm-mq-cve20181652-dos (144724)"
}
]
},
"data_type" : "CVE",
"data_format" : "MITRE",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Denial of Service"
}
]
}
]
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"product_name" : "DataPower Gateways",
"version" : {
"version_data" : [
{
"version_value" : "7.1.0.0"
},
{
"version_value" : "7.2.0.0"
},
{
"version_value" : "7.5.0.0"
},
{
"version_value" : "7.5.1.0"
},
{
"version_value" : "7.6.0.0"
},
{
"version_value" : "7.5.2.0"
},
{
"version_value" : "7.6.0.2"
},
{
"version_value" : "7.5.2.9"
},
{
"version_value" : "7.5.1.9"
},
{
"version_value" : "7.5.0.10"
},
{
"version_value" : "7.2.0.16"
},
{
"version_value" : "7.1.0.19"
}
]
}
},
{
"version" : {
"version_data" : [
{
"version_value" : "9.0.1"
},
{
"version_value" : "9.0.5"
},
{
"version_value" : "8.0.0.0"
},
{
"version_value" : "8.0.0.8"
}
]
},
"product_name" : "MQ Appliance"
}
]
}
}
]
}
}
}

View File

@ -1,18 +1,102 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1654",
"STATE" : "RESERVED"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 144747.",
"lang" : "eng"
}
]
}
},
"CVE_data_meta" : {
"STATE" : "PUBLIC",
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2018-12-06T00:00:00",
"ID" : "CVE-2018-1654"
},
"references" : {
"reference_data" : [
{
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10739027",
"refsource" : "CONFIRM",
"title" : "IBM Security Bulletin 739027 (Curam Social Program Management)",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10739027"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/144747",
"title" : "X-Force Vulnerability Report",
"name" : "ibm-curam-cve20181654-open-redirect (144747)",
"refsource" : "XF"
}
]
},
"impact" : {
"cvssv3" : {
"BM" : {
"I" : "H",
"S" : "C",
"C" : "N",
"UI" : "R",
"SCORE" : "6.800",
"PR" : "L",
"AV" : "N",
"A" : "N",
"AC" : "L"
},
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "U"
}
}
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"product_name" : "Curam Social Program Management",
"version" : {
"version_data" : [
{
"version_value" : "6.0.5"
},
{
"version_value" : "6.1.1"
},
{
"version_value" : "6.2.0"
},
{
"version_value" : "7.0.1"
},
{
"version_value" : "7.0.3"
}
]
}
}
]
}
}
]
}
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Gain Access"
}
]
}
]
},
"data_format" : "MITRE",
"data_type" : "CVE"
}

View File

@ -1,18 +1,102 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1900",
"STATE" : "RESERVED"
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Curam Social Program Management",
"version" : {
"version_data" : [
{
"version_value" : "6.0.5"
},
{
"version_value" : "6.1.1"
},
{
"version_value" : "6.2.0"
},
{
"version_value" : "7.0.1"
},
{
"version_value" : "7.0.4"
}
]
}
}
]
},
"vendor_name" : "IBM"
}
]
}
},
"data_format" : "MITRE",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Cross-Site Scripting",
"lang" : "eng"
}
]
}
]
},
"data_type" : "CVE",
"references" : {
"reference_data" : [
{
"refsource" : "CONFIRM",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10739035",
"title" : "IBM Security Bulletin 739035 (Curam Social Program Management)",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10739035"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/152529",
"title" : "X-Force Vulnerability Report",
"refsource" : "XF",
"name" : "ibm-curam-cve20181900-xss (152529)"
}
]
},
"data_version" : "4.0",
"CVE_data_meta" : {
"STATE" : "PUBLIC",
"ID" : "CVE-2018-1900",
"DATE_PUBLIC" : "2018-12-06T00:00:00",
"ASSIGNER" : "psirt@us.ibm.com"
},
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152529."
}
]
},
"impact" : {
"cvssv3" : {
"BM" : {
"I" : "L",
"S" : "C",
"SCORE" : "5.400",
"UI" : "R",
"C" : "L",
"PR" : "L",
"AV" : "N",
"A" : "N",
"AC" : "L"
},
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "H"
}
}
}
}

View File

@ -1,17 +1,98 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1904",
"STATE" : "RESERVED"
"data_type" : "CVE",
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "WebSphere Application Server",
"version" : {
"version_data" : [
{
"version_value" : "7.0"
},
{
"version_value" : "8.0"
},
{
"version_value" : "8.5"
},
{
"version_value" : "9.0"
}
]
}
}
]
},
"vendor_name" : "IBM"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Gain Access"
}
]
}
]
},
"impact" : {
"cvssv3" : {
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "U"
},
"BM" : {
"C" : "H",
"UI" : "N",
"SCORE" : "8.100",
"PR" : "N",
"I" : "H",
"S" : "U",
"AC" : "H",
"AV" : "N",
"A" : "H"
}
}
},
"data_version" : "4.0",
"CVE_data_meta" : {
"STATE" : "PUBLIC",
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2018-12-10T00:00:00",
"ID" : "CVE-2018-1904"
},
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533."
}
]
},
"references" : {
"reference_data" : [
{
"url" : "https://www-01.ibm.com/support/docview.wss?uid=ibm10738735",
"refsource" : "CONFIRM",
"name" : "https://www-01.ibm.com/support/docview.wss?uid=ibm10738735",
"title" : "IBM Security Bulletin 0738735"
},
{
"name" : "ibm-websphere-cve20181904-code-exec (152533)",
"refsource" : "XF",
"title" : "X-Force Vulnerability Report",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/152533"
}
]
}