mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-06-08 05:58:08 +00:00
IBM20200720-10039
Added CVE-2020-4466, CVE-2020-4361, CVE-2020-4527
This commit is contained in:
parent
4789de0ec2
commit
f130588061
@ -1,18 +1,90 @@
|
|||||||
{
|
{
|
||||||
"data_type": "CVE",
|
"impact" : {
|
||||||
"data_format": "MITRE",
|
"cvssv3" : {
|
||||||
"data_version": "4.0",
|
"TM" : {
|
||||||
"CVE_data_meta": {
|
"E" : "U",
|
||||||
"ID": "CVE-2020-4361",
|
"RC" : "C",
|
||||||
"ASSIGNER": "cve@mitre.org",
|
"RL" : "O"
|
||||||
"STATE": "RESERVED"
|
|
||||||
},
|
},
|
||||||
"description": {
|
"BM" : {
|
||||||
"description_data": [
|
"PR" : "L",
|
||||||
|
"A" : "N",
|
||||||
|
"I" : "N",
|
||||||
|
"S" : "U",
|
||||||
|
"SCORE" : "4.300",
|
||||||
|
"AV" : "N",
|
||||||
|
"AC" : "L",
|
||||||
|
"UI" : "N",
|
||||||
|
"C" : "L"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"description" : {
|
||||||
|
"description_data" : [
|
||||||
{
|
{
|
||||||
"lang": "eng",
|
"lang" : "eng",
|
||||||
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
|
"value" : "IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addresses in HTTP responses. IBM X-Force ID: 178766."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_format" : "MITRE",
|
||||||
|
"CVE_data_meta" : {
|
||||||
|
"ASSIGNER" : "psirt@us.ibm.com",
|
||||||
|
"ID" : "CVE-2020-4361",
|
||||||
|
"DATE_PUBLIC" : "2020-07-17T00:00:00",
|
||||||
|
"STATE" : "PUBLIC"
|
||||||
|
},
|
||||||
|
"references" : {
|
||||||
|
"reference_data" : [
|
||||||
|
{
|
||||||
|
"refsource" : "CONFIRM",
|
||||||
|
"url" : "https://www.ibm.com/support/pages/node/6249981",
|
||||||
|
"title" : "IBM Security Bulletin 6249981 (Planning Analytics)",
|
||||||
|
"name" : "https://www.ibm.com/support/pages/node/6249981"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name" : "ibm-planning-cve20204361-info-disc (178766)",
|
||||||
|
"title" : "X-Force Vulnerability Report",
|
||||||
|
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/178766",
|
||||||
|
"refsource" : "XF"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_type" : "CVE",
|
||||||
|
"data_version" : "4.0",
|
||||||
|
"problemtype" : {
|
||||||
|
"problemtype_data" : [
|
||||||
|
{
|
||||||
|
"description" : [
|
||||||
|
{
|
||||||
|
"lang" : "eng",
|
||||||
|
"value" : "Obtain Information"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"affects" : {
|
||||||
|
"vendor" : {
|
||||||
|
"vendor_data" : [
|
||||||
|
{
|
||||||
|
"product" : {
|
||||||
|
"product_data" : [
|
||||||
|
{
|
||||||
|
"version" : {
|
||||||
|
"version_data" : [
|
||||||
|
{
|
||||||
|
"version_value" : "2.0"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"product_name" : "Planning Analytics"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"vendor_name" : "IBM"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
@ -1,18 +1,93 @@
|
|||||||
{
|
{
|
||||||
"data_type": "CVE",
|
"impact" : {
|
||||||
"data_format": "MITRE",
|
"cvssv3" : {
|
||||||
"data_version": "4.0",
|
"BM" : {
|
||||||
"CVE_data_meta": {
|
"SCORE" : "6.500",
|
||||||
"ID": "CVE-2020-4466",
|
"S" : "U",
|
||||||
"ASSIGNER": "cve@mitre.org",
|
"C" : "N",
|
||||||
"STATE": "RESERVED"
|
"UI" : "N",
|
||||||
|
"AV" : "N",
|
||||||
|
"AC" : "L",
|
||||||
|
"A" : "H",
|
||||||
|
"PR" : "L",
|
||||||
|
"I" : "N"
|
||||||
},
|
},
|
||||||
"description": {
|
"TM" : {
|
||||||
"description_data": [
|
"RL" : "O",
|
||||||
|
"E" : "U",
|
||||||
|
"RC" : "C"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"data_format" : "MITRE",
|
||||||
|
"description" : {
|
||||||
|
"description_data" : [
|
||||||
{
|
{
|
||||||
"lang": "eng",
|
"value" : "IBM MQ for HPE NonStop 8.0.4 and 8.1.0 could allow a remote authenticated attacker could cause a denial of service due to an error within the Queue processing function. IBM X-Force ID: 181563.",
|
||||||
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
|
"lang" : "eng"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_type" : "CVE",
|
||||||
|
"CVE_data_meta" : {
|
||||||
|
"ID" : "CVE-2020-4466",
|
||||||
|
"DATE_PUBLIC" : "2020-07-17T00:00:00",
|
||||||
|
"STATE" : "PUBLIC",
|
||||||
|
"ASSIGNER" : "psirt@us.ibm.com"
|
||||||
|
},
|
||||||
|
"references" : {
|
||||||
|
"reference_data" : [
|
||||||
|
{
|
||||||
|
"refsource" : "CONFIRM",
|
||||||
|
"title" : "IBM Security Bulletin 6250473 (MQ for HPE NonStop)",
|
||||||
|
"url" : "https://www.ibm.com/support/pages/node/6250473",
|
||||||
|
"name" : "https://www.ibm.com/support/pages/node/6250473"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name" : "ibm-mq-cve20204466-dos (181563)",
|
||||||
|
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/181563",
|
||||||
|
"title" : "X-Force Vulnerability Report",
|
||||||
|
"refsource" : "XF"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"affects" : {
|
||||||
|
"vendor" : {
|
||||||
|
"vendor_data" : [
|
||||||
|
{
|
||||||
|
"product" : {
|
||||||
|
"product_data" : [
|
||||||
|
{
|
||||||
|
"version" : {
|
||||||
|
"version_data" : [
|
||||||
|
{
|
||||||
|
"version_value" : "8.1.0"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"version_value" : "8.0.4"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"product_name" : "MQ for HPE NonStop"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"vendor_name" : "IBM"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
"problemtype" : {
|
||||||
|
"problemtype_data" : [
|
||||||
|
{
|
||||||
|
"description" : [
|
||||||
|
{
|
||||||
|
"lang" : "eng",
|
||||||
|
"value" : "Denial of Service"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_version" : "4.0"
|
||||||
}
|
}
|
@ -1,18 +1,90 @@
|
|||||||
{
|
{
|
||||||
"data_type": "CVE",
|
"references" : {
|
||||||
"data_format": "MITRE",
|
"reference_data" : [
|
||||||
"data_version": "4.0",
|
|
||||||
"CVE_data_meta": {
|
|
||||||
"ID": "CVE-2020-4527",
|
|
||||||
"ASSIGNER": "cve@mitre.org",
|
|
||||||
"STATE": "RESERVED"
|
|
||||||
},
|
|
||||||
"description": {
|
|
||||||
"description_data": [
|
|
||||||
{
|
{
|
||||||
"lang": "eng",
|
"name" : "https://www.ibm.com/support/pages/node/6249981",
|
||||||
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
|
"refsource" : "CONFIRM",
|
||||||
|
"title" : "IBM Security Bulletin 6249981 (Planning Analytics)",
|
||||||
|
"url" : "https://www.ibm.com/support/pages/node/6249981"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name" : "ibm-planning-cve20204527-info-disc (182631)",
|
||||||
|
"refsource" : "XF",
|
||||||
|
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/182631",
|
||||||
|
"title" : "X-Force Vulnerability Report"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"CVE_data_meta" : {
|
||||||
|
"ASSIGNER" : "psirt@us.ibm.com",
|
||||||
|
"STATE" : "PUBLIC",
|
||||||
|
"ID" : "CVE-2020-4527",
|
||||||
|
"DATE_PUBLIC" : "2020-07-17T00:00:00"
|
||||||
|
},
|
||||||
|
"data_type" : "CVE",
|
||||||
|
"data_version" : "4.0",
|
||||||
|
"problemtype" : {
|
||||||
|
"problemtype_data" : [
|
||||||
|
{
|
||||||
|
"description" : [
|
||||||
|
{
|
||||||
|
"value" : "Obtain Information",
|
||||||
|
"lang" : "eng"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"affects" : {
|
||||||
|
"vendor" : {
|
||||||
|
"vendor_data" : [
|
||||||
|
{
|
||||||
|
"product" : {
|
||||||
|
"product_data" : [
|
||||||
|
{
|
||||||
|
"product_name" : "Planning Analytics",
|
||||||
|
"version" : {
|
||||||
|
"version_data" : [
|
||||||
|
{
|
||||||
|
"version_value" : "2.0"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"vendor_name" : "IBM"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"impact" : {
|
||||||
|
"cvssv3" : {
|
||||||
|
"TM" : {
|
||||||
|
"RC" : "C",
|
||||||
|
"E" : "U",
|
||||||
|
"RL" : "O"
|
||||||
|
},
|
||||||
|
"BM" : {
|
||||||
|
"UI" : "N",
|
||||||
|
"AV" : "N",
|
||||||
|
"AC" : "H",
|
||||||
|
"C" : "H",
|
||||||
|
"SCORE" : "5.900",
|
||||||
|
"S" : "U",
|
||||||
|
"I" : "N",
|
||||||
|
"PR" : "N",
|
||||||
|
"A" : "N"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"description" : {
|
||||||
|
"description_data" : [
|
||||||
|
{
|
||||||
|
"lang" : "eng",
|
||||||
|
"value" : "IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the Secure flag for the session cookie in TLS mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and obtain sensitive information. IBM X-Force ID: 182631."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_format" : "MITRE"
|
||||||
}
|
}
|
Loading…
x
Reference in New Issue
Block a user