René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

192 lines
6.9 KiB
JSON

{
"id": "CVE-2015-7472",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2016-02-15T02:59:12.310",
"lastModified": "2016-12-03T03:12:57.130",
"vulnStatus": "Modified",
"evaluatorComment": "CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') - https://cwe.mitre.org/data/definitions/90.html",
"descriptions": [
{
"lang": "en",
"value": "IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors."
},
{
"lang": "es",
"value": "IBM WebSphere Portal 6.1.0 hasta la versi\u00f3n 6.1.0.6 CF27, 6.1.5 hasta la versi\u00f3n 6.1.5.3 CF27, 7.0.0 hasta la versi\u00f3n 7.0.0.2 CF29, 8.0.0 en versiones anteriores a 8.0.0.1 CF20 y 8.5.0 en versiones anteriores a CF10 permite a atacantes remotos llevar a cabo ataques de inyecci\u00f3n LDAP, y consecuentemente leer o escribir en los datos de repositorio, a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 7.2,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 2.7
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 6.4
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "E618064A-3D05-4DC6-9A47-0EDF2427642F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "3DE74154-3E79-4D56-96C4-D8E644F1419D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "FA915826-5D89-43E9-83E7-88973648302A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "C5DB29F4-59AB-439C-91C4-CDF677676C26"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "9D6CA922-11EF-4315-A09A-B4A8937E4CF4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.5:*:*:*:*:*:*:*",
"matchCriteriaId": "526738D7-1AF8-4A8F-B833-BA0E35973A3E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.6:*:*:*:*:*:*:*",
"matchCriteriaId": "13D6BE9C-16FD-4FB4-8A87-56B42C246316"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3F1964FC-672F-4139-938F-A8EF9D86D9C2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "C5B50CEA-AFC4-4B45-9954-519965237FC3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.2:*:*:*:*:*:*:*",
"matchCriteriaId": "0902AC0F-EA4D-4E65-A70A-15DE9B904B35"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.3:*:*:*:*:*:*:*",
"matchCriteriaId": "D808F95D-C6BD-43EB-B16C-66449977BCFE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D303B0B9-CDAB-409B-AE44-512D4791C36F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "C6ECEE98-B276-4ED6-AA5A-109EA57E9925"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "9E4FF84B-A17F-464B-A718-67C44D2C69BC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C90EF7A4-8181-42C3-BB95-395D0DD94C14"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "1F40E0F5-B964-4BDC-828E-7571619F7C5B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_portal:8.5.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D03AF20E-0C29-45A6-9B7F-8260D8D9E8BF"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1PI53426",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21972736",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securitytracker.com/id/1035324",
"source": "psirt@us.ibm.com"
}
]
}