René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

106 lines
3.7 KiB
JSON

{
"id": "CVE-2014-0873",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2014-03-16T14:06:45.193",
"lastModified": "2017-08-29T01:34:18.340",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de CSRF en las interfaces (1) Data Stewardship, (2) Business Admin y (3) Product en el servidor de IBM InfoSphere Master Data Management (MDM) 8.5 anterior a 8.5.0.82, 9.0.1 anterior a 9.0.1.38, 9.0.2 anterior a 9.0.2.35, 10.0 anterior a 10.0.0.0.26 y 10.1 anterior a 10.1.0.0.15 permiten a atacantes remotos secuestrar la autenticaci\u00f3n de usuarios arbitrarios."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server:8.5:*:*:*:*:*:*:*",
"matchCriteriaId": "0D8A8904-AB69-4DAE-B840-973BEAB95E3F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server:9.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "6806874E-B69D-4BEF-9815-A9744C4B1757"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server:9.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "C5534816-7062-4D6A-B296-618F6407C2CD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F63F3246-E93E-4AFE-9E95-A27180A3B8B4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:infosphere_master_data_management_server:10.1:*:*:*:*:*:*:*",
"matchCriteriaId": "B176246A-FFAD-46E5-ACED-144925A35CFE"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21666462",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90994",
"source": "psirt@us.ibm.com"
}
]
}