mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
95 lines
2.9 KiB
JSON
95 lines
2.9 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"STATE": "PUBLIC",
|
|
"ID": "CVE-2019-4381",
|
|
"DATE_PUBLIC": "2019-06-12T00:00:00",
|
|
"ASSIGNER": "psirt@us.ibm.com"
|
|
},
|
|
"impact": {
|
|
"cvssv3": {
|
|
"TM": {
|
|
"RL": "O",
|
|
"RC": "C",
|
|
"E": "U"
|
|
},
|
|
"BM": {
|
|
"AV": "L",
|
|
"I": "N",
|
|
"AC": "H",
|
|
"UI": "N",
|
|
"C": "H",
|
|
"PR": "N",
|
|
"SCORE": "5.900",
|
|
"A": "N",
|
|
"S": "C"
|
|
}
|
|
}
|
|
},
|
|
"data_format": "MITRE",
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"title": "IBM Security Bulletin 887369 (i)",
|
|
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10887369",
|
|
"refsource": "CONFIRM",
|
|
"name": "https://www.ibm.com/support/docview.wss?uid=ibm10887369"
|
|
},
|
|
{
|
|
"title": "X-Force Vulnerability Report",
|
|
"refsource": "XF",
|
|
"name": "ibm-i-cve20194381-info-disc (162159)",
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/162159"
|
|
},
|
|
{
|
|
"refsource": "BID",
|
|
"name": "108808",
|
|
"url": "http://www.securityfocus.com/bid/108808"
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "IBM",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "i",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "7.27.3"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Obtain Information"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159."
|
|
}
|
|
]
|
|
},
|
|
"data_version": "4.0",
|
|
"data_type": "CVE"
|
|
} |