98 lines
3.0 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2008-4294",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-09-27T10:30:03.570",
"lastModified": "2017-08-08T01:32:32.187",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation, as demonstrated by a root session that is still valid after a subsequent read-only session has begun."
},
{
"lang": "es",
"value": "IBM Tivoli Netcool/Webtop v2.1 antes de v2.1.0.5 preserva privilegios de usuario cacheados despu\u00e9s de cerrar sesi\u00f3n, lo cual permite a atacantes aproximarse f\u00edsicamente para secuestrar una sesi\u00f3n visitando una workstation desatendida, como se demuestra por una sesi\u00f3n ra\u00edz que es a\u00fan v\u00e1lida despu\u00e9s de que una sesi\u00f3n posterior de s\u00f3lo lectura se haya iniciado."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:tivoli_netcool_webtop:2.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A303AACF-6137-4AE8-A541-F52F0BA9D8A5"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg24018932",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1IZ21888",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/31414",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2690",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45419",
"source": "cve@mitre.org"
}
]
}