2024-07-14 02:06:08 +00:00

211 lines
7.5 KiB
JSON

{
"id": "CVE-2012-2684",
"sourceIdentifier": "secalert@redhat.com",
"published": "2012-09-28T17:55:00.913",
"lastModified": "2021-07-15T19:16:09.750",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en la funci\u00f3n get_sample_filters_by_signature en Cumin antes de v0.1.5444, tal y como se utiliza en Red Hat Enterprise Messaging, Realtime y Grid (MRG) v2.0 permiten la ejecuci\u00f3n remota de SQL arbitrarias a trav\u00e9s de (1) el id del agente (2) el id del objeto."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.1.5192-4",
"matchCriteriaId": "EB8CE3E6-C78F-4363-B731-A7981046EE5B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.3160-1:*:*:*:*:*:*:*",
"matchCriteriaId": "B33C6617-24FB-4C96-A786-D26B074B0569"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4369-1:*:*:*:*:*:*:*",
"matchCriteriaId": "D6CF3F68-713E-48E8-8D37-4AE443AF87FC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4410-2:*:*:*:*:*:*:*",
"matchCriteriaId": "8BDF4FB8-5ECF-4A2F-8066-8C362574B55F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4494-1:*:*:*:*:*:*:*",
"matchCriteriaId": "6ADC326A-3CE8-4710-870B-BF540CCB4A5E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4794-1:*:*:*:*:*:*:*",
"matchCriteriaId": "FFB4776E-178C-4488-9C98-98859576E343"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4916-1:*:*:*:*:*:*:*",
"matchCriteriaId": "77B6E427-B880-48EB-8139-2F54381539BB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5033-1:*:*:*:*:*:*:*",
"matchCriteriaId": "9EABF881-94BA-4E76-8EDB-29A4DB7F68B1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5037-1:*:*:*:*:*:*:*",
"matchCriteriaId": "476B4482-38CB-46FB-B05D-CBBCDA87B739"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5054-1:*:*:*:*:*:*:*",
"matchCriteriaId": "F49E39C4-D9D4-44D0-9F24-2DB3EB1E4457"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5068-1:*:*:*:*:*:*:*",
"matchCriteriaId": "75A69413-E0B0-4528-8C42-898866BD3B9B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5092-1:*:*:*:*:*:*:*",
"matchCriteriaId": "00B69A8C-A652-4CBB-80B1-171630C7420E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5098-2:*:*:*:*:*:*:*",
"matchCriteriaId": "11E7AFB1-7864-47D4-AD75-9B9950BE7BBB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5105-1:*:*:*:*:*:*:*",
"matchCriteriaId": "B9C553FD-1ED7-436A-B4A7-309C79CB7793"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-1:*:*:*:*:*:*:*",
"matchCriteriaId": "4CBBA885-F992-464D-9DF4-047F824FC02B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-2:*:*:*:*:*:*:*",
"matchCriteriaId": "D313A509-35AE-4EA3-9EDC-20CA98293D99"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-3:*:*:*:*:*:*:*",
"matchCriteriaId": "B84531E0-D82D-43AE-A708-B12C34984B70"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-4:*:*:*:*:*:*:*",
"matchCriteriaId": "9106FF80-627C-40E1-80E1-E574EB9A6B8C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-5:*:*:*:*:*:*:*",
"matchCriteriaId": "F46220E7-B924-49D4-B866-3EA6B52F4D45"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5192-1:*:*:*:*:*:*:*",
"matchCriteriaId": "CACA1231-8272-40A9-B7B3-0141E0F1D7A7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C60FA8B1-1802-4522-A088-22171DCF7A93"
}
]
}
]
}
],
"references": [
{
"url": "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830245",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.html",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-1278.html",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-1281.html",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/50660",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/55618",
"source": "secalert@redhat.com"
}
]
}