René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

102 lines
3.2 KiB
JSON

{
"id": "CVE-2007-3495",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-06-29T18:30:00.000",
"lastModified": "2018-10-16T16:50:11.037",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in the SAP Internet Communication Framework (BC-MID-ICF) in the SAP Basis component 700 before SP12, and 640 before SP20, allow remote attackers to inject arbitrary web script or HTML via certain parameters associated with the default login error page."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en SAP Internet Communication Framework (BC-MID-ICF) en el componente de SAP Basis 700 anterior a SP12, y 640 anterior a SP20, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n mediante ciertos par\u00e1metros asociados con la p\u00e1gina de error por defecto del inicio de sesi\u00f3n."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:sap_basis_component_640:*:*:*:*:*:*:*:*",
"versionEndIncluding": "sp19",
"matchCriteriaId": "6AEEB988-54CE-4E13-AA3B-7C1C73732777"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:sap_basis_component_700:*:*:*:*:*:*:*:*",
"versionEndIncluding": "sp11",
"matchCriteriaId": "FE706CA3-FA62-4706-96E4-5FE0278A3ED3"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/2849",
"source": "cve@mitre.org"
},
{
"url": "http://www.csnc.ch/advisory/sap02.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/472345/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2381",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35107",
"source": "cve@mitre.org"
}
]
}