mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
231 lines
8.2 KiB
JSON
231 lines
8.2 KiB
JSON
{
|
|
"id": "CVE-2014-0919",
|
|
"sourceIdentifier": "psirt@us.ibm.com",
|
|
"published": "2015-05-08T01:59:00.080",
|
|
"lastModified": "2016-11-28T19:10:42.190",
|
|
"vulnStatus": "Modified",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "IBM DB2 9.5 hasta 10.5 en Linux, UNIX, y Windows almacena contrase\u00f1as durante el procesamiento de ciertas declaraciones SQL mediante las instalaciones de monitorizaci\u00f3n y auditoria, lo que permite a usuarios remotos autenticados obtener informaci\u00f3n sensible a trav\u00e9s de comandos asociados con estas instalaciones."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "SINGLE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 4.0
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.0,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-200"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:advanced_enterprise:*:*:*",
|
|
"matchCriteriaId": "7D6DD3FF-5AD3-4D39-9CEE-838630A45C61"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:advanced_workgroup:*:*:*",
|
|
"matchCriteriaId": "AD3706B1-232E-411A-9F42-452CEF827341"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:enterprise:*:*:*",
|
|
"matchCriteriaId": "0AEA6FC2-8A75-4C22-92B8-8F7243B20886"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "70DD1608-0865-451C-989C-67D7E7FDADBB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.5:*:*:*:workgroup:*:*:*",
|
|
"matchCriteriaId": "55AB0632-CDAF-43CB-A614-33E5687D6A45"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*",
|
|
"matchCriteriaId": "3D9E7D2A-42B9-4D07-A107-BBD839E59858"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*",
|
|
"matchCriteriaId": "FD27164C-7554-46E1-B755-27C74D2EC3B7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*",
|
|
"matchCriteriaId": "F199F7B4-F273-4D45-AE08-7B5DAE6E0794"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "ACEB3F4A-6411-4456-9B89-A43562189BD3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*",
|
|
"matchCriteriaId": "1749B7DC-08BB-474B-BA5A-52602459C8EC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_enterprise:*:*:*",
|
|
"matchCriteriaId": "025FA405-0FD2-4B19-8FA4-15581085BD15"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_workgroup:*:*:*",
|
|
"matchCriteriaId": "F425C545-39CD-483C-97A3-BE0DC3EE63DB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:enterprise:*:*:*",
|
|
"matchCriteriaId": "6A6A7680-D883-414F-965B-1D6136760CA5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "76107CFE-EB32-4AF6-9AF9-F16238F9C671"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:9.8:*:*:*:workgroup:*:*:*",
|
|
"matchCriteriaId": "7D1225B0-DBFF-4A13-93CB-1B64AF9ACE47"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_enterprise:*:*:*",
|
|
"matchCriteriaId": "2ECC11D3-7D77-4823-8B34-DD76E131D74C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_workgroup:*:*:*",
|
|
"matchCriteriaId": "E1D36687-32AF-43E2-97D9-FDF602F89318"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:enterprise:*:*:*",
|
|
"matchCriteriaId": "DD80ADF4-35D3-4534-AACD-C00D80870723"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "8D274B00-C986-4A5D-94B2-79F4A613D951"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.1:*:*:*:workgroup:*:*:*",
|
|
"matchCriteriaId": "67A935CA-7AF6-4DA9-958E-DF4BC8E2B3BF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_enterprise:*:*:*",
|
|
"matchCriteriaId": "A6B1A4DC-7062-4349-8D1A-3DE4B0E68FC8"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_workgroup:*:*:*",
|
|
"matchCriteriaId": "B3681F43-F23B-413D-B871-A40821F4988B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:enterprise:*:*:*",
|
|
"matchCriteriaId": "AE645126-ECD0-40FB-B2BA-5C9EF33EBE69"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "9AFEA656-426C-4F18-9737-8985531C7A93"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:db2:10.5:*:*:*:workgroup:*:*:*",
|
|
"matchCriteriaId": "09B0333F-0E27-40B3-A0DC-618BEA97CBC2"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07397",
|
|
"source": "psirt@us.ibm.com"
|
|
},
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07547",
|
|
"source": "psirt@us.ibm.com"
|
|
},
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07552",
|
|
"source": "psirt@us.ibm.com"
|
|
},
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07553",
|
|
"source": "psirt@us.ibm.com"
|
|
},
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IT07554",
|
|
"source": "psirt@us.ibm.com"
|
|
},
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21698021",
|
|
"source": "psirt@us.ibm.com",
|
|
"tags": [
|
|
"Patch",
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/74217",
|
|
"source": "psirt@us.ibm.com"
|
|
},
|
|
{
|
|
"url": "http://www.securitytracker.com/id/1032247",
|
|
"source": "psirt@us.ibm.com"
|
|
}
|
|
]
|
|
} |