René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

207 lines
6.8 KiB
JSON

{
"id": "CVE-2018-1999",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2019-04-08T15:29:00.920",
"lastModified": "2019-10-09T23:39:30.260",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 154889."
},
{
"lang": "es",
"value": "IBM Business Automation Workflow en las versiones 18.0.0.0, 18.0.0.1 y 18.0.0.2, podr\u00eda revelar informaci\u00f3n confidencial de la versi\u00f3n sobre el servidor desde p\u00e1ginas de error que podr\u00edan ayudar a un atacante en futuros ataques contra el sistema. ID de IBM X-Force: 154889."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
},
{
"source": "psirt@us.ibm.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_automation_workflow:18.0.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "B1D36993-75D4-4EDE-8748-A3FDE4C69DF3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_automation_workflow:18.0.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "10B802CE-F898-4B60-9E2C-4D271F9211C7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_automation_workflow:18.0.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "FBD82AD2-FE98-4716-A60A-50554620A509"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:*:*:*:*:*:*:*:*",
"versionStartIncluding": "8.0.0.0",
"versionEndIncluding": "8.0.1.3",
"matchCriteriaId": "D7F25B9A-6BC9-474D-9EFD-80955C972F58"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:*:*:*:*:*:*:*:*",
"versionStartIncluding": "8.5.0.0",
"versionEndIncluding": "8.5.0.2",
"matchCriteriaId": "EC98B343-9E03-4056-8EB0-899B7A80CC88"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.5.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7021B830-3EE4-446D-8D87-BBD2097A023E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8ED3C32B-7397-434D-B084-E92C7C6E2FE2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:cf1:*:*:*:*:*:*",
"matchCriteriaId": "6131DC1F-CBA6-4025-B5A5-98307274FA33"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:cf2:*:*:*:*:*:*",
"matchCriteriaId": "439A4F14-76E6-4A21-A23C-D3DA243585A9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.5.7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "E245DD24-5C1E-4CF0-993D-0D79A5152594"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.5.7.0:cf2017.06:*:*:*:*:*:*",
"matchCriteriaId": "4B1024F5-71EE-4484-8F78-525EE9FF2CCE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.6.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "324A0484-C50D-4400-B6FD-23D793F032AD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:business_process_manager:8.6.0.0:cf2018.03:*:*:*:*:*:*",
"matchCriteriaId": "8777DECA-6331-49BC-A579-252B079615EB"
}
]
}
]
}
],
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/154889",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory",
"VDB Entry"
]
},
{
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10870502",
"source": "psirt@us.ibm.com",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}