2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2017-1170" ,
"sourceIdentifier" : "psirt@us.ibm.com" ,
"published" : "2017-04-26T17:59:00.250" ,
2024-11-23 07:09:57 +00:00
"lastModified" : "2024-11-21T03:21:26.350" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad en IBM WebSphere Commerce Enterprise, Professional, Express y Developer 8.0 podr\u00eda permitir a un atacante local secuestrar la sesi\u00f3n de un usuario. IBM X-Force ID: 123230."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" ,
2024-11-23 07:09:57 +00:00
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-11-23 07:09:57 +00:00
"availabilityImpact" : "LOW"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.4
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P" ,
2024-11-23 07:09:57 +00:00
"baseScore" : 4.6 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "LOCAL" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-11-23 07:09:57 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE2E7243-19A2-47B2-905E-47219F08F4EB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C534568E-A611-472C-9399-15FC66D875C8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AEF3D419-A12C-4A21-9796-DBB73D638E91"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "87504CD1-92DA-4847-BDA7-013622CA7AB1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "625E1896-9035-46F3-957B-83FB128F90F2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F3AC68C-CCA2-495D-AE21-04C937CD5340"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E56CE80F-A7E1-4BE0-9679-BB4F94362B06"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF3C8F33-D613-4183-ABE1-5A3A08C16BE1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44B5F593-BE92-4E37-9EE9-42C05FA87DF9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "58D19E4D-A256-44D5-A8D8-7C9F3A64B09B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "12961C31-63AD-4AA8-8267-E003F985CE95"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0D9D8DAA-285C-4ED1-A602-412725FD79AA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C75B5188-E337-4240-9834-92C11DCE9DA7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA2E3F22-60F9-4B70-9485-6DDAC7FE4496"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8902699B-AE6A-44A4-838A-28F3EB62881B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB50A02C-E75F-4602-BDAA-FA4CBEE9CB0E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FEC536A-498B-439F-927E-B72314F8B0A8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AE0A8CAD-D5DD-45DE-900F-046673002D3B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "17E1895E-384D-4EF3-A395-7AFFC22E46CA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "438E93D2-502F-4569-AB8A-EFECA403798F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "64287718-D7AD-425B-B7B7-A6442BFD5671"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F1523569-2A23-4689-BE59-F74E678A8B2B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A9F4B2FD-14BA-46D9-B09F-1DABBA88FF1D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "57B22C48-3347-422C-9730-0A9442645D20"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6BDA8ACF-4134-434E-A5FD-39A587DE27FB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6CFB25F3-6FD7-45C9-AFCF-FAB034107E19"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E7BCC81A-B7DA-40B9-B883-A00DF9CE585B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.1.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6F8C98FD-E4AB-4BC8-9729-652294B1DF24"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "73A754F0-1328-48EF-B3C6-8435EC11D680"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6A3DF211-CE2D-47AE-BADA-A75F28B6961C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.3.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D87DB29B-5FC7-496A-B20E-99A644D8A073"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:websphere_commerce:8.0.3.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "038D04C7-A19F-4EB6-91AE-A8890F8FFEA1"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.ibm.com/support/docview.wss?uid=swg22001225" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/98027" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1038359" ,
"source" : "psirt@us.ibm.com"
2024-11-23 07:09:57 +00:00
} ,
{
"url" : "http://www.ibm.com/support/docview.wss?uid=swg22001225" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/98027" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1038359" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}