2024-04-04 08:46:00 +00:00

81 lines
2.4 KiB
JSON

{
"id": "CVE-2022-44014",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-12-25T05:15:10.683",
"lastModified": "2022-12-30T22:02:48.033",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to fetch arbitrary SQL tables. This leaks all user passwords and MSSQL hashes via /DS/LM_API/api/SelectionService/GetPaggedTab."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en Simmeth Lieferantenmanager antes de la versi\u00f3n 5.6. En el dise\u00f1o de la API, un usuario es inherentemente capaz de recuperar tablas SQL arbitrarias. Esto filtra todas las contrase\u00f1as de usuario y hashes de MSSQL a trav\u00e9s de /DS/LM_API/api/SelectionService/GetPaggedTab."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:simmeth:lieferantenmanager:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.6",
"matchCriteriaId": "1EBB9357-82B6-40F4-BD60-52AFCF6F183A"
}
]
}
]
}
],
"references": [
{
"url": "https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-simmeth-system-gmbh-lieferantenmanager/",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}