2025-02-23 03:03:59 +00:00

60 lines
1.9 KiB
JSON

{
"id": "CVE-2025-0799",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2025-02-06T01:15:09.580",
"lastModified": "2025-02-06T01:15:09.580",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM App Connect enterprise\u00a012.0.1.0 through 12.0.12.10 and\u00a013.0.1.0 through 13.0.2.1\u00a0could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment due to improper pathname limitations on restricted directories."
},
{
"lang": "es",
"value": "IBM App Connect Enterprise 12.0.1.0 a 12.0.12.10 y 13.0.1.0 a 13.0.2.1 podr\u00edan permitir que un usuario autenticado escriba en un archivo arbitrario en el sistema durante la implementaci\u00f3n de la configuraci\u00f3n de la barra debido a limitaciones de ruta de acceso incorrectas en directorios restringidos."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "psirt@us.ibm.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "psirt@us.ibm.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7182418",
"source": "psirt@us.ibm.com"
}
]
}