René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

149 lines
5.1 KiB
JSON

{
"id": "CVE-2020-14232",
"sourceIdentifier": "psirt@hcl.com",
"published": "2020-12-18T00:15:14.237",
"lastModified": "2020-12-21T21:47:37.477",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el manejo del par\u00e1metro de entrada de HCL Notes versi\u00f3n v9, podr\u00eda ser explotada potencialmente por un atacante autenticado, resultando en un desbordamiento del b\u00fafer de la pila. Esto podr\u00eda permitir a un atacante bloquear el programa o inyectar c\u00f3digo en el sistema que podr\u00eda ser ejecutado con los privilegios del usuario actualmente registrado"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "19015D39-9117-4A6E-BCD7-0951CB185399"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:-:*:*:*:*:*:*",
"matchCriteriaId": "978E309F-453B-4D9D-8D15-5A6919E8D178"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10:*:*:*:*:*:*",
"matchCriteriaId": "2C984E7E-ADF7-4F52-9CE1-A6F1E05A4140"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if1:*:*:*:*:*:*",
"matchCriteriaId": "DAD49650-9091-4706-9CAF-51BABDFB94CC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if2:*:*:*:*:*:*",
"matchCriteriaId": "6CE02BCC-5280-4065-8CD9-0BC2A2821335"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if3:*:*:*:*:*:*",
"matchCriteriaId": "CF1C4C44-7B5E-4405-9F49-B85957E88760"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if4:*:*:*:*:*:*",
"matchCriteriaId": "8CAA8D2D-7A27-49B5-87D2-740E6EB286A6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if5:*:*:*:*:*:*",
"matchCriteriaId": "A5778563-769B-40A2-8830-E64A5F18CE3C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if6:*:*:*:*:*:*",
"matchCriteriaId": "6B69E327-0C81-4233-9791-DD50F66E9293"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if7:*:*:*:*:*:*",
"matchCriteriaId": "331AD3B5-8D54-469A-873C-73AF93BC35DF"
}
]
}
]
}
],
"references": [
{
"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085883",
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
]
}
]
}