2024-12-08 03:06:42 +00:00

105 lines
3.5 KiB
JSON

{
"id": "CVE-2010-0155",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-09-14T17:00:01.480",
"lastModified": "2024-11-21T01:11:38.673",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n CRLF (se refiere a CR (retorno de carro) y LF (salto de l\u00ednea)) en Local Management Interface (LMI) en el dispositivo IBM Proventia Network Mail Security System (PNMSS) con firmware anterior a la versi\u00f3n 2.5 permite a atacantes remotos autenticados inyectar cabeceras HTTP de su elecci\u00f3n y llevar a cabo ataques de separaci\u00f3n de respuesta HTTP a trav\u00e9s del par\u00e1metro \"javaVersion\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"baseScore": 3.5,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.8,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:proventia_network_mail_security_system_virtual_appliance:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E4AE7B81-387C-446B-B5EF-B897C39D15A1"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:proventia_network_mail_security_system_virtual_appliance_firmware:1.6:*:*:*:*:*:*:*",
"matchCriteriaId": "D3A62936-C40C-40DF-8222-ABD6D287CAC5"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/archive/1/513636/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.ventuneac.net/security-advisories/MVSA-10-009",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/513636/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ventuneac.net/security-advisories/MVSA-10-009",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"evaluatorImpact": "Per: http://www.ventuneac.net/security-advisories/MVSA-10-009\r\n\r\nAffected Versions\r\n\r\nIBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)"
}