mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
90 lines
2.7 KiB
JSON
90 lines
2.7 KiB
JSON
{
|
|
"data_format": "MITRE",
|
|
"data_version": "4.0",
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "IBM",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "4"
|
|
}
|
|
]
|
|
},
|
|
"product_name": "Security Guardium Big Data Intelligence"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"value": "IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 161209.",
|
|
"lang": "eng"
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"name": "https://www.ibm.com/support/pages/node/1096906",
|
|
"refsource": "CONFIRM",
|
|
"title": "IBM Security Bulletin 1096906 (Security Guardium Big Data Intelligence)",
|
|
"url": "https://www.ibm.com/support/pages/node/1096906"
|
|
},
|
|
{
|
|
"title": "X-Force Vulnerability Report",
|
|
"refsource": "XF",
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/161209",
|
|
"name": "ibm-guardium-cve20194329-sec-bypass (161209)"
|
|
}
|
|
]
|
|
},
|
|
"impact": {
|
|
"cvssv3": {
|
|
"TM": {
|
|
"RC": "C",
|
|
"RL": "O",
|
|
"E": "U"
|
|
},
|
|
"BM": {
|
|
"AV": "N",
|
|
"C": "N",
|
|
"UI": "N",
|
|
"A": "N",
|
|
"AC": "L",
|
|
"S": "U",
|
|
"SCORE": "4.300",
|
|
"PR": "L",
|
|
"I": "L"
|
|
}
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Bypass Security"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2019-4329",
|
|
"DATE_PUBLIC": "2019-10-23T00:00:00",
|
|
"ASSIGNER": "psirt@us.ibm.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"data_type": "CVE"
|
|
} |