cvelist/2019/4xxx/CVE-2019-4329.json
2019-10-29 19:01:09 +00:00

90 lines
2.7 KiB
JSON

{
"data_format": "MITRE",
"data_version": "4.0",
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "IBM",
"product": {
"product_data": [
{
"version": {
"version_data": [
{
"version_value": "4"
}
]
},
"product_name": "Security Guardium Big Data Intelligence"
}
]
}
}
]
}
},
"description": {
"description_data": [
{
"value": "IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 161209.",
"lang": "eng"
}
]
},
"references": {
"reference_data": [
{
"name": "https://www.ibm.com/support/pages/node/1096906",
"refsource": "CONFIRM",
"title": "IBM Security Bulletin 1096906 (Security Guardium Big Data Intelligence)",
"url": "https://www.ibm.com/support/pages/node/1096906"
},
{
"title": "X-Force Vulnerability Report",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/161209",
"name": "ibm-guardium-cve20194329-sec-bypass (161209)"
}
]
},
"impact": {
"cvssv3": {
"TM": {
"RC": "C",
"RL": "O",
"E": "U"
},
"BM": {
"AV": "N",
"C": "N",
"UI": "N",
"A": "N",
"AC": "L",
"S": "U",
"SCORE": "4.300",
"PR": "L",
"I": "L"
}
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Bypass Security"
}
]
}
]
},
"CVE_data_meta": {
"ID": "CVE-2019-4329",
"DATE_PUBLIC": "2019-10-23T00:00:00",
"ASSIGNER": "psirt@us.ibm.com",
"STATE": "PUBLIC"
},
"data_type": "CVE"
}