mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 17:21:36 +00:00
143 lines
4.8 KiB
JSON
143 lines
4.8 KiB
JSON
{
|
|
"id": "CVE-2014-3077",
|
|
"sourceIdentifier": "psirt@us.ibm.com",
|
|
"published": "2014-09-15T14:55:11.260",
|
|
"lastModified": "2017-08-29T01:34:38.263",
|
|
"vulnStatus": "Modified",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "IBM SONAS y System Storage Storwize V7000 Unified (tambi\u00e9n conocido como V7000U) 1.3.x y 1.4.x anterior a 1.4.3.4 almacena la contrase\u00f1a chkauth en el registro de auditor\u00eda, lo que permite a usuarios locales obtener informaci\u00f3n sensible mediante la lectura del registro."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
|
|
"accessVector": "LOCAL",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 2.1
|
|
},
|
|
"baseSeverity": "LOW",
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-200"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.3.0.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C2890B04-AB96-4B1F-90B0-3F365FD6EF0D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.3.2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DE9CC5C3-AE3E-4A24-B35B-3CD35D6D4414"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.3.2.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BAEA5EAD-5341-429C-9DD4-DEB311485D68"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.0.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1F9B4C74-9135-4775-AC09-D79BEFF2BD3E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.0.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E1420861-4678-4282-BFD7-5933C48269F6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "02299B18-7BD4-4F39-A5FA-6FFE92F9A12D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4C1FF672-811A-43AF-B7C8-61FF78952B7F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "63BD0102-EDB1-46D6-9EF1-D4002BCDBE14"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.3.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D522173E-9C93-445A-B0DA-B11614C2DDCD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:storwize_v7000_unified_software:1.4.3.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BBA57121-8A60-41CB-B767-59A516772DB0"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:h:ibm:storwize_unified_v7000:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "969B07CF-DEB1-4463-B361-D6A49642F75A"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004837",
|
|
"source": "psirt@us.ibm.com",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/93906",
|
|
"source": "psirt@us.ibm.com"
|
|
}
|
|
]
|
|
} |