René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

160 lines
5.0 KiB
JSON

{
"id": "CVE-2020-4290",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2020-04-08T14:15:13.413",
"lastModified": "2020-04-08T18:22:06.957",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333."
},
{
"lang": "es",
"value": "IBM Security Information Queue (ISIQ) versiones 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4 y 1.0.5, podr\u00eda permitir a cualquier usuario autenticado falsificar la configuraci\u00f3n del propietario de cualquier otro usuario que revele informaci\u00f3n confidencial o permita un acceso no autorizado. ID de IBM X-Force: 176333."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 2.5
}
],
"cvssMetricV30": [
{
"source": "psirt@us.ibm.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 4.2,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.6,
"impactScore": 2.5
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 5.5
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-290"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_information_queue:1.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A9C1648E-DC06-40C1-9402-DCEA495EA56E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_information_queue:1.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "6AC11E98-3C57-436E-B47A-B5EE0ED200CD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_information_queue:1.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "44CEB32A-9E8E-429B-8196-CE3028B10846"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_information_queue:1.0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "02D9F72B-B893-4E2C-993E-13873859269D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_information_queue:1.0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "A82CC708-3CB3-4BBB-82EF-181C18ED522B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:security_information_queue:1.0.5:*:*:*:*:*:*:*",
"matchCriteriaId": "F4B1900B-4568-4017-B0A3-9B43C484ED31"
}
]
}
]
}
],
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/176333",
"source": "psirt@us.ibm.com",
"tags": [
"VDB Entry",
"Vendor Advisory"
]
},
{
"url": "https://www.ibm.com/support/pages/node/6172599",
"source": "psirt@us.ibm.com",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}