cvelist/2020/5xxx/CVE-2020-5022.json
2021-01-08 20:02:00 +00:00

93 lines
2.8 KiB
JSON

{
"CVE_data_meta": {
"ID": "CVE-2020-5022",
"DATE_PUBLIC": "2021-01-07T00:00:00",
"STATE": "PUBLIC",
"ASSIGNER": "psirt@us.ibm.com"
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"value": "Obtain Information",
"lang": "eng"
}
]
}
]
},
"data_type": "CVE",
"data_version": "4.0",
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"name": "https://www.ibm.com/support/pages/node/6398754",
"url": "https://www.ibm.com/support/pages/node/6398754",
"title": "IBM Security Bulletin 6398754 (Spectrum Protect Plus)"
},
{
"title": "X-Force Vulnerability Report",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/193658",
"name": "ibm-spectrum-cve20205022-info-disc (193658)",
"refsource": "XF"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access. IBM X-Force ID: 193658."
}
]
},
"data_format": "MITRE",
"impact": {
"cvssv3": {
"TM": {
"RL": "O",
"RC": "C",
"E": "U"
},
"BM": {
"C": "L",
"AC": "L",
"PR": "N",
"UI": "N",
"SCORE": "5.300",
"A": "N",
"S": "U",
"AV": "N",
"I": "N"
}
}
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Spectrum Protect Plus",
"version": {
"version_data": [
{
"version_value": "10.1.0"
},
{
"version_value": "10.1.6"
}
]
}
}
]
},
"vendor_name": "IBM"
}
]
}
}
}