134 lines
5.2 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2022-38754",
"sourceIdentifier": "security@opentext.com",
2023-04-24 12:24:31 +02:00
"published": "2022-12-08T16:15:11.717",
"lastModified": "2024-11-21T07:17:01.747",
"vulnStatus": "Modified",
"cveTags": [],
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the Operations Bridge Manager capability is deployed. A potential vulnerability has been identified in Micro Focus Operations Bridge Manager (OBM). The vulnerability could be exploited by a malicious authenticated OBM user to run Java Scripts in the browser context of another OBM user. This issue affects: Micro Focus Micro Focus Operations Bridge Manager versions prior to 2022.11. Micro Focus Micro Focus Operations Bridge- Containerized versions prior to 2022.11."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad potencial en Micro Focus Operations Bridge - Containerized. La vulnerabilidad podr\u00eda ser aprovechada por un usuario malicioso de OBM (Operations Bridge Manager) autenticado para ejecutar Java Scripts en el contexto del navegador de otro usuario de OBM. Tenga en cuenta: la vulnerabilidad solo es aplicable si se implementa la capacidad de Operations Bridge Manager. Se ha identificado una vulnerabilidad potencial en Micro Focus Operations Bridge Manager (OBM). La vulnerabilidad podr\u00eda ser aprovechada por un usuario malicioso de OBM autenticado para ejecutar Java Scripts en el contexto del navegador de otro usuario de OBM. Este problema afecta a: Versiones de Micro Focus Micro Focus Operations Bridge Manager anteriores a 2022.11. Micro Focus Micro Focus Operations Bridge: versiones en contenedores anteriores a 2022.11."
2023-04-24 12:24:31 +02:00
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@opentext.com",
"type": "Secondary",
2023-04-24 12:24:31 +02:00
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 8.0,
"baseSeverity": "HIGH",
2023-04-24 12:24:31 +02:00
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
2023-04-24 12:24:31 +02:00
},
"exploitabilityScore": 2.1,
"impactScore": 5.9
2023-04-24 12:24:31 +02:00
},
{
"source": "nvd@nist.gov",
"type": "Primary",
2023-04-24 12:24:31 +02:00
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
2023-04-24 12:24:31 +02:00
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
2023-04-24 12:24:31 +02:00
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
2023-04-24 12:24:31 +02:00
}
]
},
"weaknesses": [
{
"source": "security@opentext.com",
"type": "Secondary",
2023-04-24 12:24:31 +02:00
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
2023-04-24 12:24:31 +02:00
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microfocus:operations_bridge:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2022.11",
"matchCriteriaId": "AC94A857-6EFE-42B2-83B8-1B92370997D9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microfocus:operations_bridge_manager:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2022.11",
"matchCriteriaId": "7ED2BA42-B9F9-4CB5-81FF-2077642280C1"
}
]
}
]
}
],
"references": [
{
"url": "https://marketplace.microfocus.com/itom/content/operations-bridge-manager-obm-2022-05-hotfixes",
"source": "security@opentext.com"
2023-04-24 12:24:31 +02:00
},
{
"url": "https://portal.microfocus.com/s/article/KM000012517?language=en_US",
"source": "security@opentext.com"
2023-04-24 12:24:31 +02:00
},
{
"url": "https://portal.microfocus.com/s/article/KM000012518?language=en_US",
"source": "security@opentext.com"
},
{
"url": "https://marketplace.microfocus.com/itom/content/operations-bridge-manager-obm-2022-05-hotfixes",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://portal.microfocus.com/s/article/KM000012517?language=en_US",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://portal.microfocus.com/s/article/KM000012518?language=en_US",
"source": "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}