2024-12-08 03:06:42 +00:00

151 lines
4.7 KiB
JSON

{
"id": "CVE-2020-15507",
"sourceIdentifier": "cve@mitre.org",
"published": "2020-07-07T02:15:10.753",
"lastModified": "2024-11-21T05:05:39.827",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad arbitraria de lectura de archivos en MobileIron Core y Connector versiones 10.3.0.3 y anteriores, versiones 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 y versi\u00f3n 10.6.0.0 que permite a atacantes remotos leer archivos sobre el sistema por medio de vectores no especificados"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mobileiron:cloud:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.6",
"matchCriteriaId": "8C4F0B0B-388C-4B6A-B233-77269AFE887E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mobileiron:core:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.6",
"matchCriteriaId": "3ACD8393-2E8F-4790-B142-1C41D2EA0956"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mobileiron:enterprise_connector:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.6",
"matchCriteriaId": "1F1D3A8A-BCA4-4DF8-A126-F9E10B194ED0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mobileiron:reporting_database:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.6",
"matchCriteriaId": "0B823AB8-E08B-4A3B-BABF-3E9FB7C18B99"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mobileiron:sentry:*:*:*:*:*:*:*:*",
"versionEndIncluding": "10.6",
"matchCriteriaId": "96937DB3-B17C-4718-B2D9-6219B5B10676"
}
]
}
]
}
],
"references": [
{
"url": "https://www.mobileiron.com/en/blog/mobileiron-security-updates-available",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.mobileiron.com/en/blog/mobileiron-security-updates-available",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.mobileiron.com/en/blog/mobileiron-security-updates-available",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.mobileiron.com/en/blog/mobileiron-security-updates-available",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}