René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

144 lines
4.7 KiB
JSON

{
"id": "CVE-2017-2766",
"sourceIdentifier": "security_alert@emc.com",
"published": "2017-02-03T07:59:00.560",
"lastModified": "2017-03-09T18:40:53.700",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system."
},
{
"lang": "es",
"value": "EMC Documentum eRoom versi\u00f3n 7.4.4, EMC Documentum eRoom versi\u00f3n 7.4.4 SP1, EMC Documentum eRoom versi\u00f3n anterior a 7.4.5 P04, EMC Documentum eRoom versi\u00f3n anterior a 7.5.0 P01 incluye una vulnerabilidad no verificada de cambio de contrase\u00f1a que podr\u00eda ser explotada por usuarios malintencionados para comprometer el sistema afectado."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-640"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.4.4:*:*:*:*:*:*:*",
"matchCriteriaId": "3DD159D8-DCB0-4A27-BEFC-BFC626B2C200"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.4.4:sp1:*:*:*:*:*:*",
"matchCriteriaId": "C44A1651-72B7-446A-98CA-18BD0E4E72D0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.4.5:*:*:*:*:*:*:*",
"matchCriteriaId": "76F12875-669C-43C7-9D00-164089E27D84"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.4.5:p01:*:*:*:*:*:*",
"matchCriteriaId": "7ADC4B3E-A538-4A85-B084-AF4E47734C12"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.4.5:p02:*:*:*:*:*:*",
"matchCriteriaId": "E7E06195-1C7E-429E-8E39-CB2455741E2D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.4.5:p03:*:*:*:*:*:*",
"matchCriteriaId": "8BED2FD3-0A0E-4C89-94BB-D02434499445"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:emc:documentum_eroom:7.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "6DCE8AD3-12F1-4952-BAE7-98F0B667595F"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/archive/1/540077/30/0/threaded",
"source": "security_alert@emc.com",
"tags": [
"Patch",
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.securityfocus.com/bid/95893",
"source": "security_alert@emc.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}