2023-11-08 19:00:23 +00:00
{
"id" : "CVE-2023-5913" ,
"sourceIdentifier" : "security@opentext.com" ,
"published" : "2023-11-08T17:15:08.193" ,
2024-09-04 16:03:36 +00:00
"lastModified" : "2024-09-04T14:35:08.320" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-11-08 19:00:23 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The\u00a0vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.\n\n"
2023-11-16 19:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de asignaci\u00f3n de privilegios incorrecta en texto abierto Fortify ScanCentral DAST. La vulnerabilidad podr\u00eda aprovecharse para obtener privilegios elevados. Este problema afecta a Fortify ScanCentral DAST versiones 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1."
2023-11-08 19:00:23 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-11-16 19:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
} ,
2023-11-08 19:00:23 +00:00
{
"source" : "security@opentext.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 8.2 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 4.2
}
]
} ,
"weaknesses" : [
2023-11-16 19:00:22 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2023-11-08 19:00:23 +00:00
{
"source" : "security@opentext.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-266"
2024-09-04 16:03:36 +00:00
}
]
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-266"
2023-11-08 19:00:23 +00:00
}
]
}
] ,
2023-11-16 19:00:22 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:21.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5578907C-9142-461B-88F3-D4510D57E23A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:21.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DDE09FF8-AFDD-4F5E-AF44-FFE8854F5763"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:21.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8EF4C5A3-E698-469A-A8AB-223AC6013B1C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:22.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0926D3A0-76B2-435C-B691-58B51EDF81B7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:22.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "956F2EB1-BF27-4F42-A325-E9F91EF60E5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:22.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6DA67A67-DC1E-4FC0-8A9B-8A2192E939BB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:microfocus:fortify_scancentral_dast:23.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9BFD11CE-87C4-40A2-A6EA-80CF1D465F4B"
}
]
}
]
}
] ,
2023-11-08 19:00:23 +00:00
"references" : [
{
"url" : "https://portal.microfocus.com/s/article/KM000023500?language=en_US" ,
2023-11-16 19:00:22 +00:00
"source" : "security@opentext.com" ,
"tags" : [
"Vendor Advisory"
]
2023-11-08 19:00:23 +00:00
}
]
}