Auto-Update: 2025-01-26T17:00:19.641072+00:00

This commit is contained in:
cad-safe-bot 2025-01-26 17:03:46 +00:00
parent d789478d65
commit 99a989488f
7 changed files with 249 additions and 16 deletions

View File

@ -0,0 +1,60 @@
{
"id": "CVE-2023-38009",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2025-01-26T16:15:30.033",
"lastModified": "2025-01-26T16:15:30.033",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"attackVector": "PHYSICAL",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 0.5,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7172691",
"source": "psirt@us.ibm.com"
},
{
"url": "https://www.ibm.com/support/pages/node/7172692",
"source": "psirt@us.ibm.com"
}
]
}

View File

@ -0,0 +1,56 @@
{
"id": "CVE-2023-50945",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2025-01-26T16:15:30.523",
"lastModified": "2025-01-26T16:15:30.523",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.5,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-256"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7161947",
"source": "psirt@us.ibm.com"
}
]
}

View File

@ -0,0 +1,56 @@
{
"id": "CVE-2023-50946",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2025-01-26T16:15:30.680",
"lastModified": "2025-01-26T16:15:30.680",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7161947",
"source": "psirt@us.ibm.com"
}
]
}

View File

@ -0,0 +1,56 @@
{
"id": "CVE-2024-31906",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2025-01-26T15:15:22.770",
"lastModified": "2025-01-26T15:15:22.770",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.5,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-525"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7150662",
"source": "psirt@us.ibm.com"
}
]
}

View File

@ -2,7 +2,7 @@
"id": "CVE-2024-37070",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2024-11-19T20:15:30.693",
"lastModified": "2024-11-19T21:56:45.533",
"lastModified": "2025-01-26T16:15:30.837",
"vulnStatus": "Undergoing Analysis",
"cveTags": [],
"descriptions": [
@ -19,7 +19,7 @@
"cvssMetricV31": [
{
"source": "psirt@us.ibm.com",
"type": "Primary",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
@ -46,7 +46,7 @@
"description": [
{
"lang": "en",
"value": "CWE-359"
"value": "CWE-497"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2025-01-26T13:00:19.092553+00:00
2025-01-26T17:00:19.641072+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2025-01-26T12:15:28.613000+00:00
2025-01-26T16:15:30.837000+00:00
```
### Last Data Feed Release
@ -33,23 +33,24 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
278991
278995
```
### CVEs added in the last Commit
Recently added CVEs: `4`
- [CVE-2024-11641](CVE-2024/CVE-2024-116xx/CVE-2024-11641.json) (`2025-01-26T12:15:27.137`)
- [CVE-2024-11936](CVE-2024/CVE-2024-119xx/CVE-2024-11936.json) (`2025-01-26T12:15:28.297`)
- [CVE-2024-12334](CVE-2024/CVE-2024-123xx/CVE-2024-12334.json) (`2025-01-26T12:15:28.460`)
- [CVE-2024-13505](CVE-2024/CVE-2024-135xx/CVE-2024-13505.json) (`2025-01-26T12:15:28.613`)
- [CVE-2023-38009](CVE-2023/CVE-2023-380xx/CVE-2023-38009.json) (`2025-01-26T16:15:30.033`)
- [CVE-2023-50945](CVE-2023/CVE-2023-509xx/CVE-2023-50945.json) (`2025-01-26T16:15:30.523`)
- [CVE-2023-50946](CVE-2023/CVE-2023-509xx/CVE-2023-50946.json) (`2025-01-26T16:15:30.680`)
- [CVE-2024-31906](CVE-2024/CVE-2024-319xx/CVE-2024-31906.json) (`2025-01-26T15:15:22.770`)
### CVEs modified in the last Commit
Recently modified CVEs: `0`
Recently modified CVEs: `1`
- [CVE-2024-37070](CVE-2024/CVE-2024-370xx/CVE-2024-37070.json) (`2025-01-26T16:15:30.837`)
## Download and Usage

View File

@ -229423,6 +229423,7 @@ CVE-2023-38000,0,0,f302fe2aa8512cea31c20b4a7c58e253de1ffdc3d1be669ab1e2dc42df677
CVE-2023-38001,0,0,59813676e2bd0245d088be67c0815fc9c634dbc57499cf0f051205236327d85f,2024-11-21T08:12:40.490000
CVE-2023-38002,0,0,11fb0758eaa7b961a3a0df91d9a00e7b42b3bcc5f411b51796ef1a318b38f981,2024-11-21T08:12:40.637000
CVE-2023-38003,0,0,d84005b22fbc5b577419dd725bee31341bd9f0980a498ef6647a0b9e648a0922,2024-11-21T08:12:40.753000
CVE-2023-38009,1,1,46696e3295dfd85568c6157e2f414de7484fedabfa7a11344597db07b6f0ffc2,2025-01-26T16:15:30.033000
CVE-2023-3801,0,0,07bd937a546b791f41c481c78de785e3d588a94a54cf897593eeef06fcdda9b2,2024-11-21T08:18:05.833000
CVE-2023-38012,0,0,e9f842a877c7f1d25f0849adca9295f08cf6211c5370f958bc0b22e8d604ec96,2025-01-25T14:15:27.337000
CVE-2023-38013,0,0,32d8e0e2fc229f4abe79c04a9f5fb5656b17774982d04ef0693f0825e989f2a7,2025-01-25T14:15:27.977000
@ -239010,6 +239011,8 @@ CVE-2023-50940,0,0,51dd5ec0317820be6a625d682b7540171c694b6e5228d23f2af653f5d184a
CVE-2023-50941,0,0,4725e71079dbca2e105a847f56a3950ea08883ccc7db725a5bc78f08a8910565,2024-11-21T08:37:34.760000
CVE-2023-50943,0,0,54315abfffcf53f8ebdb98759915ba3cd53c001fedfe964d9ebc3049f78cdf67,2024-11-21T08:37:34.903000
CVE-2023-50944,0,0,160360d8570298965240e1d42cbbce948edb8f0f040d324194d43089e6acc770,2024-11-21T08:37:35.037000
CVE-2023-50945,1,1,02988f1d7102f0f7e78a40191f5bd9eb87bf87eab6aa55696dc0993e24859857,2025-01-26T16:15:30.523000
CVE-2023-50946,1,1,83c461436091b4519e4927475684cf0c58ef5ba92248556c3accb968ed1a8699,2025-01-26T16:15:30.680000
CVE-2023-50947,0,0,315931b32ba2a05ba850339c4b9bc866bd08295cc58fb47a4e8b1ba5ad042e05,2024-11-21T08:37:35.167000
CVE-2023-50948,0,0,28323826bb3c873fc57cf155c09bad077515a97a0be7d5af9707ea35ef154f81,2024-11-21T08:37:35.350000
CVE-2023-50949,0,0,2ead519dbe6f115e7717a5e0efb9d4ffe577e1234ae7a9d8dc69063a1bfd95af,2024-11-21T08:37:35.503000
@ -244748,7 +244751,7 @@ CVE-2024-11636,0,0,477a215831f10296b9ea3788441fcca038078cee1d80a9e966a40e92f5b59
CVE-2024-11637,0,0,5348ca65261140ae16ec15332c773ee06343664939e89530c0d5541b934692f4,2025-01-14T02:15:07.907000
CVE-2024-11639,0,0,b0b1970767477e87b7cf619e96fa5cb2fbca7d53895c7bdaf49d93303071061e,2025-01-17T19:40:09.763000
CVE-2024-1164,0,0,d6b3223f31512976ce37113225736cbf014a2aac3d8c295ef68c5d3e3fda5f16,2025-01-16T15:08:00.773000
CVE-2024-11641,1,1,01f4678010343b933e1608fd0753948e4b8c955f1bf3576c903c1756a3091a01,2025-01-26T12:15:27.137000
CVE-2024-11641,0,0,01f4678010343b933e1608fd0753948e4b8c955f1bf3576c903c1756a3091a01,2025-01-26T12:15:27.137000
CVE-2024-11642,0,0,e083dfd7b8388b09206f810c50ef0061b39601a9804b6746591b0dd89f756ab4,2025-01-09T11:15:10.187000
CVE-2024-11643,0,0,ae78ce4f54b48c77ffb4df12d001ddabc5e672affe5a377c6c988d0deb6a52af,2024-12-04T16:15:24.177000
CVE-2024-11644,0,0,38b2c694eddaad1da45e24d2b7150693eba2499ddb691622394ace7d3593825d,2024-12-27T19:15:07.400000
@ -245035,7 +245038,7 @@ CVE-2024-11931,0,0,f7a6a876558f96b3470ccc024544f5c77310fc07000a85f04a366895996c7
CVE-2024-11933,0,0,ff719b80c8b04b1955877df42e564ce90eac2c09e4f59c20e785f18a1e8804d6,2024-12-03T16:04:10.350000
CVE-2024-11934,0,0,744a72b875229eda9af00bf8cde59d77110b18803c7442665bf58299c9e4d643,2025-01-07T04:15:07.520000
CVE-2024-11935,0,0,f2a8d43d6f9999d38415d9b41f66ab77f7c4f7c94de5d0bc77beeed93d88f487,2024-12-04T13:15:05.910000
CVE-2024-11936,1,1,02df76ea9d377927d6bfac9532376cd1ea3846cd42ae66411de8f35f87d4e5fb,2025-01-26T12:15:28.297000
CVE-2024-11936,0,0,02df76ea9d377927d6bfac9532376cd1ea3846cd42ae66411de8f35f87d4e5fb,2025-01-26T12:15:28.297000
CVE-2024-11938,0,0,6867b7d1c50742be481431f973c83467fcdb9442488abece06649b31c7a1e61f,2024-12-21T07:15:08.453000
CVE-2024-11939,0,0,6345ccf177226852fd504f0bbd480483116e863a5c5b707e8b4952ffc0b3c45f,2025-01-08T09:15:06.630000
CVE-2024-1194,0,0,2ad6fa2abb4bb109947132f87b19e7c09219cf51535c19102f3cbbfcba6ba405,2024-11-21T08:50:00.573000
@ -245350,7 +245353,7 @@ CVE-2024-12330,0,0,dd38f32a8fe1201123bcdc5b82b5d883712c2acc7974b9580df0e29bb6562
CVE-2024-12331,0,0,1854f15311a9fd512bedfae9559249a253ffa3b6afc48825c570d85f65b5b458,2024-12-19T12:15:05.330000
CVE-2024-12332,0,0,f0bf328e81e8dc6e6391061dc5bf4110c5e0a30cef25e410954b9a99df4dbf02,2025-01-07T05:15:18.687000
CVE-2024-12333,0,0,f9b36bf24b65a5eadc34be133c8efc135d615c6b77b9af6e424c71705bac5515,2024-12-12T09:15:05.390000
CVE-2024-12334,1,1,e6b0748578dd37a10b34427150b96c94f36de22000a143e359355f2f2ad604cf,2025-01-26T12:15:28.460000
CVE-2024-12334,0,0,e6b0748578dd37a10b34427150b96c94f36de22000a143e359355f2f2ad604cf,2025-01-26T12:15:28.460000
CVE-2024-12335,0,0,811e1f31fde162cfb07e19f2dc625fd9888bd35150e2bacee10a476425d11394,2024-12-25T07:15:11.980000
CVE-2024-12337,0,0,0ac824defe049d65b98a787c3f5b6e8a7c26d83f20e6b104dc20776aaa16a0de,2025-01-08T11:15:06.613000
CVE-2024-12338,0,0,202a85d7d49dabb95d9680ff72787a60f1c4021e681feb9be8640c62beb774ef,2024-12-12T04:15:07.497000
@ -246171,7 +246174,7 @@ CVE-2024-13499,0,0,6d635dc5b8c51f2804fa43df8b3beb018f4524a3b4ba54f25865b62cf92ed
CVE-2024-1350,0,0,ce11ba75737d3c0dc14aea45038ee6ef39f1db647d13879ee3f248d09a81697f,2024-11-21T08:50:23.313000
CVE-2024-13502,0,0,b6bd5e7a8ccd125fd10c3c602ef666035a1824dda1c710321e34fb9d3259b3fe,2025-01-17T14:15:31.147000
CVE-2024-13503,0,0,ffb0135326ea2a3ea18800ce3bd83bc523a9e303f03b2acc60a1815003b2400e,2025-01-17T14:15:31.317000
CVE-2024-13505,1,1,8cfee4eef351da06016ab9b10f867ee856aa66c9481e93ffeb4ce296549af983,2025-01-26T12:15:28.613000
CVE-2024-13505,0,0,8cfee4eef351da06016ab9b10f867ee856aa66c9481e93ffeb4ce296549af983,2025-01-26T12:15:28.613000
CVE-2024-1351,0,0,0ee767ddd9bd942759d1902d3186de90141de07710cd1c9cc0aaf86395d89b28,2024-11-21T08:50:23.450000
CVE-2024-13511,0,0,3071f1ee4394ed25c0ba5a4414759a0ec6bbc3d07f1733cb6f65493d29a37d83,2025-01-23T10:15:07.253000
CVE-2024-13515,0,0,aca8f7e0638fd7d821357389659621eb450217319a62bd2c5a959e9c0aea1b39,2025-01-18T06:15:26.410000
@ -255937,6 +255940,7 @@ CVE-2024-31902,0,0,003a18851ece455ee1e6ea2a4455c0284b8742534b1304a5388aa31d40a16
CVE-2024-31903,0,0,f1559924e9af14a36520fa16f97e50e9463ab7aedc8dee1206ec2eaf945f2191,2025-01-22T16:15:29.030000
CVE-2024-31904,0,0,d2a04e1afb3ab14e7bd62c982b1ec9fbcf0becba36a47360842f1553f25b269c,2025-01-07T21:05:40.810000
CVE-2024-31905,0,0,4f1bdfcd5321f7b992df963e233e7a11fb0781b24167b44218cf69a784597a28,2024-08-28T22:08:30.560000
CVE-2024-31906,1,1,cdbab75271060c4ffdbed5374e6006f43073bcb084f72251d4d7a6687b5dc8fe,2025-01-26T15:15:22.770000
CVE-2024-31907,0,0,56360f441ba18f82366ed4eb471a5c96a8260a64fefc6012f99306629a9a97be,2025-01-08T17:06:40.250000
CVE-2024-31908,0,0,74d2a41f6e31ae19807e7a04173849b90024608a485a3ca2443e9547826e8735,2025-01-08T17:02:59.363000
CVE-2024-3191,0,0,26fefd7ee9b00b194a72c3556380217e011fbb35712e009d8c207a4a175b109d,2024-11-21T09:29:06.920000
@ -259895,7 +259899,7 @@ CVE-2024-37065,0,0,e3998bfe6e6676203c2338bffa7e5eadfbebd65f6925e4543d310214b8784
CVE-2024-37066,0,0,240837f9d82f0f01bc6ee55d7b74ae4428500497a54219c7fce44e32d094f37d,2024-11-21T09:23:08.487000
CVE-2024-37068,0,0,c3afdecda336d72de98ec07e1d7aa9f3118914e9a8f778e3cb5b72dbdf60d490,2024-09-21T10:15:05.793000
CVE-2024-3707,0,0,999dd383007b2d055934067affe146a02aeec3372415f71b35075ecab7272c50,2024-11-21T09:30:13.203000
CVE-2024-37070,0,0,6310b34e225f5fdd7253c72fa93e38adc64ac7c74d47c317701055c4c65efee1,2024-11-19T21:56:45.533000
CVE-2024-37070,0,1,c022bbfd510d9dfa3803db541238e2871b96a3963a669fa0a3bab8924a1c69d4,2025-01-26T16:15:30.837000
CVE-2024-37071,0,0,a67e9eb57bb911747e859e4f8acbe6d9597b1ffb725d99346231b7b26bb39319,2024-12-07T13:15:04.047000
CVE-2024-37077,0,0,a61753e8a7bc9b974748648e270addba7b9a945731807708a3fa2aad01161089,2024-11-21T09:23:08.803000
CVE-2024-37078,0,0,bd89123a0c458e38196f44b5c84293b821a2198e363b4989eb386f33a6b35386,2024-11-21T09:23:08.943000

Can't render this file because it is too large.