2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2017-1195" ,
"sourceIdentifier" : "psirt@us.ibm.com" ,
"published" : "2017-08-29T21:29:00.527" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T03:21:28.457" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123670."
} ,
{
"lang" : "es" ,
"value" : "IBM Curam Social Program Management 6.0, 6.1, 6.2, y 7.0 podr\u00eda permitir que un atacante remoto lleve a cabo ataques de phishing empleando un ataque de redirecci\u00f3n abierta. Al persuadir a una v\u00edctima para que visite un sitio web especialmente manipulado, un atacante remoto podr\u00eda explotar esta vulnerabilidad para suplantar la URL mostrada y redirigir al usuario a un sitio web malicioso que, a priori, parecer\u00eda de confianza. Esto podr\u00eda permitir que el atacante obtuviese informaci\u00f3n sumamente sensible o que llevase a cabo m\u00e1s ataques contra la v\u00edctima. IBM X-Force ID: 123670."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.1 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.7
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 4.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-601"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AEFDBB0F-A8C9-40DF-81CF-799D034D2EE0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BB8E3B08-7171-414D-8A41-14C9E18B1BAB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "940271A7-2CC3-4A34-BB5A-D9F4D45A7895"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2F3FDC1-B49D-46DD-B9F7-DCE3F1FD4B5A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "13AA664F-BCD8-4CED-A201-E2543D437E1C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A6711519-4E7D-4782-8372-7996C24E50D6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "32D0CA3E-2649-4B4B-A805-81213FC07A12"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "510DC15C-03F8-4058-A88A-13EFC48A43C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4971ADE2-3F58-4B42-9EC6-EFF3CF967E5D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.4.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DE01821C-590F-40E1-A973-5DF0EA0151D8"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7A5F30D0-82C1-4F88-9FDB-A8E6D6D39591"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "17929DC8-0E48-4BF4-AAFE-6463C8540FF9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FD3FF4C-C12A-4CBC-8983-85929C5D121E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DAE6D88C-92CF-415E-978C-0107C4C4C52C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB928C52-91BB-43A6-B25F-F359F05F1388"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "25DE6951-4C91-4443-843C-805D416F4074"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "23EA1C1F-003F-4411-AC1D-F75811D6FFEC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E89D44FA-FE58-4A4E-8DB1-BA9667A16612"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AD0FCFA0-2443-4AE9-ACE6-394A67443808"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6D4A5540-525C-4F99-BA26-3B988B5A08D3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7C5C061E-A4F5-4478-A9E4-D8BA156085B9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.5.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "12A2D187-7B5D-44D1-A766-A972F257EF54"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AC1991AF-E483-4A6E-938B-D1B6796FF135"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6695193E-0347-4E20-A991-038CC3BA6386"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3B972B5E-6825-4DD5-8BB6-851DFFBB5109"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B3C202FC-EA69-429B-85C6-F58A093C901F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "71CB6F37-6F14-4313-82D8-7D1EF110852D"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "89A3A8B1-8088-4FCC-A38C-96526201F159"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F666549A-5879-4141-A97F-347B52755092"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "808EF0E6-842C-4E81-8743-01230D32532C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7020B7F8-0C57-4533-B49F-559058A23CAB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D5887540-4EBE-484E-9C5B-3EFA0950BE30"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1E303C07-8CB1-4EF8-82F3-4C2B3C664812"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2923B5C1-78A5-4A0D-B18E-DAC59B62EBA4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.2.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "58610A13-D6F7-49BA-A576-350DACC5C86F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.2.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FAA53735-7E72-4717-9168-38286B5261E3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:6.2.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1CB504DC-E137-4026-BB16-E862045BD380"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:7.0.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "180CE3A7-BA57-49B4-8103-20E12CD37435"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:curam_social_program_management:7.0.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8C0DF071-1EB8-49FD-A279-A895A45B4679"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.ibm.com/support/docview.wss?uid=swg22007160" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/123670" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"VDB Entry" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://www.ibm.com/support/docview.wss?uid=swg22007160" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/123670" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"VDB Entry" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}