René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

126 lines
4.3 KiB
JSON

{
"id": "CVE-2014-3061",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2014-08-26T14:55:05.813",
"lastModified": "2017-08-29T01:34:37.437",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences."
},
{
"lang": "es",
"value": "Vulnerabilidad de CSRF en IBM Emptoris Spend Analysis 9.5.x anterior a 9.5.0.4, 10.0.1.x anterior a 10.0.1.3, y 10.0.2.x anterior a 10.0.2.4 permite a atacantes remotos secuestrar la autenticaci\u00f3n de usuarios arbitrarios para solicitudes que insertan secuencias de XSS."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "1173E8F6-A85E-452C-9B36-89427D57DDF0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "BD21D4C5-5180-4AE0-A11F-009A6CF1EFA0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "8EC42DEB-FA8D-42C4-ACDC-0A5036939B2E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:9.5.0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "DE122AF0-070A-41EE-980C-C55BF1A7995F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "501E457B-084A-4E3B-981A-01B19B28B0B1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "54F1BCFD-6DCD-4427-AC89-638588878713"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "1C2FD0BD-DFFF-4512-A290-EACBC82EFB04"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "251FE42A-D7C2-415A-8356-F0B1A141147A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:emptoris_spend_analysis:10.0.2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "A975908E-A3C9-4F2C-AE37-66F6F54239DA"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21681277",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/93537",
"source": "psirt@us.ibm.com"
}
]
}