IBM20181206-8544

Added CVE-2018-1525, CVE-2018-1871, CVE-2018-1935, CVE-2018-1505, CVE-2018-1504
This commit is contained in:
Scott Moore - IBM 2018-12-06 08:05:44 -05:00
parent 5d4ddb0787
commit ea10b3d5e9
No known key found for this signature in database
GPG Key ID: 95B9EA1B824C2926
5 changed files with 417 additions and 45 deletions

View File

@ -1,17 +1,89 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1504",
"STATE" : "RESERVED"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"CVE_data_meta" : {
"ID" : "CVE-2018-1504",
"ASSIGNER" : "psirt@us.ibm.com",
"DATE_PUBLIC" : "2018-12-05T00:00:00",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "2.1.7"
}
]
},
"product_name" : "i2 Enterprise Insight Analysis"
}
]
},
"vendor_name" : "IBM"
}
]
}
},
"references" : {
"reference_data" : [
{
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10738699",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10738699",
"title" : "IBM Security Bulletin 738699 (i2 Enterprise Insight Analysis)",
"refsource" : "CONFIRM"
},
{
"name" : "ibm-i2-cve20181504-clickjacking (141340)",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/141340",
"refsource" : "XF",
"title" : "X-Force Vulnerability Report"
}
]
},
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 141340."
}
]
},
"impact" : {
"cvssv3" : {
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "H"
},
"BM" : {
"AC" : "L",
"I" : "L",
"UI" : "R",
"AV" : "N",
"A" : "N",
"SCORE" : "6.100",
"S" : "C",
"C" : "L",
"PR" : "N"
}
}
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Gain Access",
"lang" : "eng"
}
]
}
]
}

View File

@ -1,18 +1,90 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1505",
"STATE" : "RESERVED"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"impact" : {
"cvssv3" : {
"BM" : {
"AC" : "L",
"I" : "N",
"A" : "N",
"UI" : "N",
"AV" : "L",
"C" : "L",
"SCORE" : "4.000",
"S" : "U",
"PR" : "N"
},
"TM" : {
"RC" : "C",
"RL" : "O",
"E" : "U"
}
}
},
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "Obtain Information"
}
]
}
]
},
"CVE_data_meta" : {
"DATE_PUBLIC" : "2018-12-05T00:00:00",
"STATE" : "PUBLIC",
"ID" : "CVE-2018-1505",
"ASSIGNER" : "psirt@us.ibm.com"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "2.1.7"
}
]
},
"product_name" : "i2 Enterprise Insight Analysis"
}
]
},
"vendor_name" : "IBM"
}
]
}
},
"references" : {
"reference_data" : [
{
"refsource" : "CONFIRM",
"title" : "IBM Security Bulletin 738699 (i2 Enterprise Insight Analysis)",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10738699",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10738699"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/141413",
"name" : "ibm-i2-cve20181505-info-disc (141413)",
"title" : "X-Force Vulnerability Report",
"refsource" : "XF"
}
]
},
"data_version" : "4.0",
"data_type" : "CVE"
}

View File

@ -1,18 +1,90 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1525",
"STATE" : "RESERVED"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
"problemtype" : {
"problemtype_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"description" : [
{
"value" : "Obtain Information",
"lang" : "eng"
}
]
}
]
},
"description" : {
"description_data" : [
{
"value" : "IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142117.",
"lang" : "eng"
}
]
},
"impact" : {
"cvssv3" : {
"BM" : {
"PR" : "N",
"SCORE" : "5.900",
"S" : "U",
"C" : "H",
"AV" : "N",
"UI" : "N",
"A" : "N",
"AC" : "H",
"I" : "N"
},
"TM" : {
"RC" : "C",
"RL" : "O",
"E" : "U"
}
}
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "2.1.7"
}
]
},
"product_name" : "i2 Enterprise Insight Analysis"
}
]
}
}
]
}
},
"data_version" : "4.0",
"references" : {
"reference_data" : [
{
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10738699",
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10738699",
"title" : "IBM Security Bulletin 738699 (i2 Enterprise Insight Analysis)",
"refsource" : "CONFIRM"
},
{
"name" : "ibm-i2-cve20181525-info-disc (142117)",
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/142117",
"title" : "X-Force Vulnerability Report",
"refsource" : "XF"
}
]
},
"CVE_data_meta" : {
"DATE_PUBLIC" : "2018-12-05T00:00:00",
"STATE" : "PUBLIC",
"ASSIGNER" : "psirt@us.ibm.com",
"ID" : "CVE-2018-1525"
},
"data_type" : "CVE"
}

View File

@ -1,18 +1,96 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1871",
"STATE" : "RESERVED"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"value" : "IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.",
"lang" : "eng"
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "Cross-Site Scripting"
}
]
}
]
},
"impact" : {
"cvssv3" : {
"TM" : {
"RC" : "C",
"RL" : "O",
"E" : "H"
},
"BM" : {
"AC" : "L",
"I" : "L",
"AV" : "N",
"UI" : "R",
"A" : "N",
"SCORE" : "5.400",
"S" : "C",
"C" : "L",
"PR" : "L"
}
}
},
"references" : {
"reference_data" : [
{
"title" : "IBM Security Bulletin 743123 (Financial Transaction Manager)",
"refsource" : "CONFIRM",
"name" : "http://www.ibm.com/support/docview.wss?uid=ibm10743123",
"url" : "http://www.ibm.com/support/docview.wss?uid=ibm10743123"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/151329",
"name" : "ibm-ftm-cve20181871-xss (151329)",
"refsource" : "XF",
"title" : "X-Force Vulnerability Report"
}
]
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "3.0.2"
},
{
"version_value" : "3.0.5"
},
{
"version_value" : "3.0.0"
}
]
},
"product_name" : "Financial Transaction Manager"
}
]
}
}
]
}
},
"CVE_data_meta" : {
"ASSIGNER" : "psirt@us.ibm.com",
"ID" : "CVE-2018-1871",
"DATE_PUBLIC" : "2018-12-04T00:00:00",
"STATE" : "PUBLIC"
},
"data_version" : "4.0",
"data_type" : "CVE"
}

View File

@ -1,18 +1,96 @@
{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2018-1935",
"STATE" : "RESERVED"
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value" : "IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"value" : "Obtain Information",
"lang" : "eng"
}
]
}
]
},
"impact" : {
"cvssv3" : {
"TM" : {
"RL" : "O",
"RC" : "C",
"E" : "U"
},
"BM" : {
"PR" : "L",
"C" : "L",
"S" : "U",
"SCORE" : "4.300",
"A" : "N",
"AV" : "N",
"UI" : "N",
"AC" : "L",
"I" : "N"
}
}
},
"data_type" : "CVE",
"data_version" : "4.0",
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "IBM",
"product" : {
"product_data" : [
{
"version" : {
"version_data" : [
{
"version_value" : "5.0"
},
{
"version_value" : "5.5"
},
{
"version_value" : "6.0"
}
]
},
"product_name" : "Connections"
}
]
}
}
]
}
},
"references" : {
"reference_data" : [
{
"name" : "https://www.ibm.com/support/docview.wss?uid=ibm10742575",
"url" : "https://www.ibm.com/support/docview.wss?uid=ibm10742575",
"refsource" : "CONFIRM",
"title" : "IBM Security Bulletin 742575 (Connections)"
},
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/153315",
"name" : "ibm-connections-cve20181935-info-disc (153315)",
"title" : "X-Force Vulnerability Report",
"refsource" : "XF"
}
]
},
"CVE_data_meta" : {
"DATE_PUBLIC" : "2018-12-03T00:00:00",
"STATE" : "PUBLIC",
"ASSIGNER" : "psirt@us.ibm.com",
"ID" : "CVE-2018-1935"
},
"data_format" : "MITRE"
}