"-Synchronized-Data."

This commit is contained in:
CVE Team 2019-06-19 14:00:50 +00:00
parent 1a1fa8f594
commit e2fb471c04
No known key found for this signature in database
GPG Key ID: 0DA1F9F56BC892E8
8 changed files with 566 additions and 460 deletions

View File

@ -1,99 +1,99 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2019-06-17T00:00:00",
"STATE" : "PUBLIC",
"ID" : "CVE-2017-1107"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "9.1.2"
},
{
"version_value" : "10.0"
},
{
"version_value" : "9.1.0"
},
{
"version_value" : "10.1"
}
]
},
"product_name" : "Marketing Platform"
}
]
},
"vendor_name" : "IBM"
}
]
}
},
"data_type" : "CVE",
"impact" : {
"cvssv3" : {
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "U"
},
"BM" : {
"S" : "U",
"C" : "L",
"I" : "N",
"SCORE" : "4.300",
"PR" : "L",
"AV" : "N",
"UI" : "N",
"A" : "N",
"AC" : "L"
}
}
},
"data_format" : "MITRE",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906."
}
]
},
"references" : {
"reference_data" : [
{
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10887815",
"title" : "IBM Security Bulletin 887815 (Marketing Platform)",
"refsource" : "CONFIRM",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10887815"
},
{
"name" : "ibm-marketing-cve20171107-info-disc (120906)",
"refsource" : "XF",
"title" : "X-Force Vulnerability Report",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/120906"
}
]
},
"data_version" : "4.0",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Obtain Information",
"lang" : "eng"
}
"CVE_data_meta": {
"ASSIGNER": "psirt@us.ibm.com",
"DATE_PUBLIC": "2019-06-17T00:00:00",
"STATE": "PUBLIC",
"ID": "CVE-2017-1107"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"version": {
"version_data": [
{
"version_value": "9.1.2"
},
{
"version_value": "10.0"
},
{
"version_value": "9.1.0"
},
{
"version_value": "10.1"
}
]
},
"product_name": "Marketing Platform"
}
]
},
"vendor_name": "IBM"
}
]
}
]
}
}
}
},
"data_type": "CVE",
"impact": {
"cvssv3": {
"TM": {
"RL": "O",
"RC": "C",
"E": "U"
},
"BM": {
"S": "U",
"C": "L",
"I": "N",
"SCORE": "4.300",
"PR": "L",
"AV": "N",
"UI": "N",
"A": "N",
"AC": "L"
}
}
},
"data_format": "MITRE",
"description": {
"description_data": [
{
"lang": "eng",
"value": "IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906."
}
]
},
"references": {
"reference_data": [
{
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10887815",
"title": "IBM Security Bulletin 887815 (Marketing Platform)",
"refsource": "CONFIRM",
"name": "https://www.ibm.com/support/docview.wss?uid=ibm10887815"
},
{
"name": "ibm-marketing-cve20171107-info-disc (120906)",
"refsource": "XF",
"title": "X-Force Vulnerability Report",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/120906"
}
]
},
"data_version": "4.0",
"problemtype": {
"problemtype_data": [
{
"description": [
{
"value": "Obtain Information",
"lang": "eng"
}
]
}
]
}
}

View File

@ -1,17 +1,61 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2019-10257",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ID": "CVE-2019-10257",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash notation) to access files or directories that are elsewhere on the system. Through this vulnerability it is possible to read the application's java sources from /WEB-INF/classes/*.class"
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"name": "http://www.sk-it.com/en/cve.html",
"url": "http://www.sk-it.com/en/cve.html"
}
]
}

View File

@ -1,17 +1,61 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2019-12814",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ID": "CVE-2019-12814",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"name": "https://github.com/FasterXML/jackson-databind/issues/2341",
"url": "https://github.com/FasterXML/jackson-databind/issues/2341"
}
]
}

View File

@ -0,0 +1,18 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2019-12883",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
}
]
}
}

View File

@ -1,90 +1,90 @@
{
"CVE_data_meta" : {
"ID" : "CVE-2019-4303",
"STATE" : "PUBLIC",
"DATE_PUBLIC" : "2019-06-17T00:00:00",
"ASSIGNER" : "psirt@us.ibm.com"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"impact" : {
"cvssv3" : {
"BM" : {
"SCORE" : "5.400",
"C" : "L",
"I" : "L",
"S" : "C",
"A" : "N",
"AC" : "L",
"UI" : "R",
"AV" : "N",
"PR" : "L"
},
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "H"
}
}
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "7.6"
}
]
},
"product_name" : "Maximo Asset Management"
}
]
},
"vendor_name" : "IBM"
"CVE_data_meta": {
"ID": "CVE-2019-4303",
"STATE": "PUBLIC",
"DATE_PUBLIC": "2019-06-17T00:00:00",
"ASSIGNER": "psirt@us.ibm.com"
},
"data_format": "MITRE",
"data_type": "CVE",
"impact": {
"cvssv3": {
"BM": {
"SCORE": "5.400",
"C": "L",
"I": "L",
"S": "C",
"A": "N",
"AC": "L",
"UI": "R",
"AV": "N",
"PR": "L"
},
"TM": {
"RL": "O",
"RC": "C",
"E": "H"
}
]
}
},
"references" : {
"reference_data" : [
{
"refsource" : "CONFIRM",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10887563",
"title" : "IBM Security Bulletin 887563 (Maximo Asset Management)",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10887563"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/160949",
"refsource" : "XF",
"name" : "ibm-maximo-cve20194303-xss (160949)",
"title" : "X-Force Vulnerability Report"
}
]
},
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Cross-Site Scripting",
"lang" : "eng"
}
}
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"version": {
"version_data": [
{
"version_value": "7.6"
}
]
},
"product_name": "Maximo Asset Management"
}
]
},
"vendor_name": "IBM"
}
]
}
]
},
"data_version" : "4.0"
}
}
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"name": "https://www.ibm.com/support/docview.wss?uid=ibm10887563",
"title": "IBM Security Bulletin 887563 (Maximo Asset Management)",
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10887563"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/160949",
"refsource": "XF",
"name": "ibm-maximo-cve20194303-xss (160949)",
"title": "X-Force Vulnerability Report"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"value": "Cross-Site Scripting",
"lang": "eng"
}
]
}
]
},
"data_version": "4.0"
}

View File

@ -1,90 +1,90 @@
{
"data_version" : "4.0",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Gain Privileges",
"lang" : "eng"
}
]
}
]
},
"description" : {
"description_data" : [
{
"value" : "IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.",
"lang" : "eng"
}
]
},
"references" : {
"reference_data" : [
{
"title" : "IBM Security Bulletin 887557 (Maximo Asset Management)",
"refsource" : "CONFIRM",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10887557",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10887557"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/161680",
"refsource" : "XF",
"name" : "ibm-maximo-cve20194364-code-exec (161680)",
"title" : "X-Force Vulnerability Report"
}
]
},
"affects" : {
"vendor" : {
"vendor_data" : [
"data_version": "4.0",
"problemtype": {
"problemtype_data": [
{
"product" : {
"product_data" : [
{
"product_name" : "Maximo Asset Management",
"version" : {
"version_data" : [
{
"version_value" : "7.6"
}
]
}
}
]
},
"vendor_name" : "IBM"
"description": [
{
"value": "Gain Privileges",
"lang": "eng"
}
]
}
]
}
},
"data_type" : "CVE",
"impact" : {
"cvssv3" : {
"TM" : {
"E" : "U",
"RC" : "C",
"RL" : "O"
},
"BM" : {
"SCORE" : "5.500",
"S" : "U",
"C" : "L",
"I" : "L",
"UI" : "R",
"A" : "L",
"AC" : "L",
"AV" : "N",
"PR" : "L"
}
}
},
"data_format" : "MITRE",
"CVE_data_meta" : {
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2019-06-17T00:00:00",
"STATE" : "PUBLIC",
"ID" : "CVE-2019-4364"
}
}
]
},
"description": {
"description_data": [
{
"value": "IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.",
"lang": "eng"
}
]
},
"references": {
"reference_data": [
{
"title": "IBM Security Bulletin 887557 (Maximo Asset Management)",
"refsource": "CONFIRM",
"name": "https://www.ibm.com/support/docview.wss?uid=ibm10887557",
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10887557"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/161680",
"refsource": "XF",
"name": "ibm-maximo-cve20194364-code-exec (161680)",
"title": "X-Force Vulnerability Report"
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Maximo Asset Management",
"version": {
"version_data": [
{
"version_value": "7.6"
}
]
}
}
]
},
"vendor_name": "IBM"
}
]
}
},
"data_type": "CVE",
"impact": {
"cvssv3": {
"TM": {
"E": "U",
"RC": "C",
"RL": "O"
},
"BM": {
"SCORE": "5.500",
"S": "U",
"C": "L",
"I": "L",
"UI": "R",
"A": "L",
"AC": "L",
"AV": "N",
"PR": "L"
}
}
},
"data_format": "MITRE",
"CVE_data_meta": {
"ASSIGNER": "psirt@us.ibm.com",
"DATE_PUBLIC": "2019-06-17T00:00:00",
"STATE": "PUBLIC",
"ID": "CVE-2019-4364"
}
}

View File

@ -1,93 +1,93 @@
{
"references" : {
"reference_data" : [
{
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10887817",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10887817",
"refsource" : "CONFIRM",
"title" : "IBM Security Bulletin 887817 (Campaign)"
},
{
"name" : "ibm-campaign-cve20194384-dir-traversal (162172)",
"refsource" : "XF",
"title" : "X-Force Vulnerability Report",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/162172"
}
]
},
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Obtain Information"
}
]
}
]
},
"data_version" : "4.0",
"CVE_data_meta" : {
"STATE" : "PUBLIC",
"ID" : "CVE-2019-4384",
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2019-06-17T00:00:00"
},
"data_format" : "MITRE",
"impact" : {
"cvssv3" : {
"BM" : {
"AV" : "N",
"PR" : "L",
"A" : "N",
"AC" : "L",
"UI" : "N",
"C" : "L",
"I" : "N",
"S" : "U",
"SCORE" : "4.300"
},
"TM" : {
"E" : "U",
"RC" : "C",
"RL" : "O"
}
}
},
"data_type" : "CVE",
"affects" : {
"vendor" : {
"vendor_data" : [
"references": {
"reference_data": [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"product_name" : "Campaign",
"version" : {
"version_data" : [
{
"version_value" : "9.1.2"
},
{
"version_value" : "10.1"
}
]
}
}
]
}
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10887817",
"name": "https://www.ibm.com/support/docview.wss?uid=ibm10887817",
"refsource": "CONFIRM",
"title": "IBM Security Bulletin 887817 (Campaign)"
},
{
"name": "ibm-campaign-cve20194384-dir-traversal (162172)",
"refsource": "XF",
"title": "X-Force Vulnerability Report",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/162172"
}
]
}
}
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Obtain Information"
}
]
}
]
},
"data_version": "4.0",
"CVE_data_meta": {
"STATE": "PUBLIC",
"ID": "CVE-2019-4384",
"ASSIGNER": "psirt@us.ibm.com",
"DATE_PUBLIC": "2019-06-17T00:00:00"
},
"data_format": "MITRE",
"impact": {
"cvssv3": {
"BM": {
"AV": "N",
"PR": "L",
"A": "N",
"AC": "L",
"UI": "N",
"C": "L",
"I": "N",
"S": "U",
"SCORE": "4.300"
},
"TM": {
"E": "U",
"RC": "C",
"RL": "O"
}
}
},
"data_type": "CVE",
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "IBM",
"product": {
"product_data": [
{
"product_name": "Campaign",
"version": {
"version_data": [
{
"version_value": "9.1.2"
},
{
"version_value": "10.1"
}
]
}
}
]
}
}
]
}
}
}

View File

@ -1,90 +1,90 @@
{
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173."
}
]
},
"references" : {
"reference_data" : [
{
"title" : "IBM Security Bulletin 886099 (Spectrum Protect Plus)",
"refsource" : "CONFIRM",
"name" : "http://www.ibm.com/support/docview.wss?uid=ibm10886099",
"url" : "http://www.ibm.com/support/docview.wss?uid=ibm10886099"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/162173",
"title" : "X-Force Vulnerability Report",
"name" : "ibm-spectrum-cve20194385-info-disc (162173)",
"refsource" : "XF"
}
]
},
"data_version" : "4.0",
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Obtain Information"
}
]
}
]
},
"CVE_data_meta" : {
"ID" : "CVE-2019-4385",
"STATE" : "PUBLIC",
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2019-06-17T00:00:00"
},
"affects" : {
"vendor" : {
"vendor_data" : [
"description": {
"description_data": [
{
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "10.1.2"
}
]
},
"product_name" : "Spectrum Protect Plus"
}
]
},
"vendor_name" : "IBM"
"lang": "eng",
"value": "IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173."
}
]
}
},
"impact" : {
"cvssv3" : {
"BM" : {
"I" : "N",
"C" : "H",
"S" : "C",
"SCORE" : "5.900",
"AV" : "L",
"PR" : "N",
"AC" : "H",
"A" : "N",
"UI" : "N"
},
"TM" : {
"RC" : "C",
"E" : "U",
"RL" : "O"
}
}
},
"data_type" : "CVE",
"data_format" : "MITRE"
}
]
},
"references": {
"reference_data": [
{
"title": "IBM Security Bulletin 886099 (Spectrum Protect Plus)",
"refsource": "CONFIRM",
"name": "http://www.ibm.com/support/docview.wss?uid=ibm10886099",
"url": "http://www.ibm.com/support/docview.wss?uid=ibm10886099"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/162173",
"title": "X-Force Vulnerability Report",
"name": "ibm-spectrum-cve20194385-info-disc (162173)",
"refsource": "XF"
}
]
},
"data_version": "4.0",
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Obtain Information"
}
]
}
]
},
"CVE_data_meta": {
"ID": "CVE-2019-4385",
"STATE": "PUBLIC",
"ASSIGNER": "psirt@us.ibm.com",
"DATE_PUBLIC": "2019-06-17T00:00:00"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"version": {
"version_data": [
{
"version_value": "10.1.2"
}
]
},
"product_name": "Spectrum Protect Plus"
}
]
},
"vendor_name": "IBM"
}
]
}
},
"impact": {
"cvssv3": {
"BM": {
"I": "N",
"C": "H",
"S": "C",
"SCORE": "5.900",
"AV": "L",
"PR": "N",
"AC": "H",
"A": "N",
"UI": "N"
},
"TM": {
"RC": "C",
"E": "U",
"RL": "O"
}
}
},
"data_type": "CVE",
"data_format": "MITRE"
}