2024-12-08 03:06:42 +00:00

84 lines
2.6 KiB
JSON

{
"id": "CVE-2009-2956",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-08-24T15:30:00.343",
"lastModified": "2024-11-21T01:06:09.270",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files."
},
{
"lang": "es",
"value": "Los componentes (1) Net.Commerce y (2) Net.Data en IBM WebSphere Commerce Suite almacenan informaci\u00f3n sensible en el directorio web ra\u00edz con un control de acceso insuficiente, permitiendo a atacantes remotos descubrir contrase\u00f1as, y detalles de la base de datos y el sistema de ficheros, mediante una petici\u00f3n directa a los ficheros de configuraci\u00f3n."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_commerce_suite:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9325A374-8168-4C9C-8A6B-FF034FB7EC30"
}
]
}
]
}
],
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52616",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52616",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}