René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

107 lines
3.8 KiB
JSON

{
"id": "CVE-2014-0861",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2014-02-22T21:55:09.877",
"lastModified": "2014-03-06T04:50:42.360",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button."
},
{
"lang": "es",
"value": "Vulnerabilidad de tipo cross-site scripting (XSS) en el servidor en Cognos Business Intelligence (BI) de IBM versi\u00f3n 8.4.1, versi\u00f3n 10.1 anterior a IF6, versi\u00f3n 10.1.1 anterior a IF5, versi\u00f3n 10.2 anterior a IF7, versi\u00f3n 10.2.1 anterior a IF4, y versi\u00f3n 10.2.1.1 anterior a IF4, permite a los atacantes remotos inyectar script web o HTML arbitrario por medio de un par\u00e1metro no especificado que no es manejado apropiadamente durante el uso del bot\u00f3n Back."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 3.5
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.8,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:8.4.1:*:*:*:*:*:*:*",
"matchCriteriaId": "2B76A06D-761D-4CFE-A9E6-FC5A1F726CF5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.1:*:*:*:*:*:*:*",
"matchCriteriaId": "519B7097-7E46-4520-B9F9-A85E13A0F9CE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "B00BAD84-4BB6-41ED-835E-86AB150716D9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*",
"matchCriteriaId": "6588FEE1-5A6F-4ED6-998A-B8CF54954F5D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FDA8132D-A09E-4D4C-9A5D-D708010CCFFD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "7CCBB0AE-ECD1-4192-B1BB-18439A4CF7B9"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21662856",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
}
]
}