René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

185 lines
5.6 KiB
JSON

{
"id": "CVE-2019-7394",
"sourceIdentifier": "vuln@ca.com",
"published": "2019-05-28T19:29:07.283",
"lastModified": "2020-10-06T14:29:32.357",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has customized and limited privileges."
},
{
"lang": "es",
"value": "Vulnerabilidad de escalado de privilegios en la interfaz de usuario administrativa de CA Technologies CA Strong Authentication 9.0. x, 8.2. x, 8.1. x, 8.0. x, 7.1. x y CA Risk Authentication 9.0. x, 8.2. x, 8.1. x, 8.0. x, 3.1. x permite que un atacante autenticado gane privilegios adicionales en algunos casos donde una cuenta tiene privilegios personalizados y limitados."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.5
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
},
{
"source": "vuln@ca.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ca:risk_authentication:*:*:*:*:*:*:*:*",
"versionStartIncluding": "8.0",
"versionEndIncluding": "8.2.1",
"matchCriteriaId": "F08DB725-FAA3-43E1-A311-6795E9223B7F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ca:risk_authentication:3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A0DB9BF7-B737-4E91-B300-8EED3E74320F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ca:risk_authentication:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3466697E-0524-49D0-B442-9AD1217E6741"
}
]
}
]
},
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ca:strong_authentication:*:*:*:*:*:*:*:*",
"versionStartIncluding": "8.0",
"versionEndIncluding": "8.2.1",
"matchCriteriaId": "FC37FEAD-CAE3-48CB-90BB-A7EDEB865F8C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ca:strong_authentication:7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "11106687-4A8C-404B-9A36-1E0D20F9B5CA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ca:strong_authentication:9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2455FD87-0FF8-47ED-93BA-23C0AC18B383"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/153089/CA-Risk-Strong-Authentication-Privilege-Escalation.html",
"source": "vuln@ca.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://seclists.org/fulldisclosure/2019/May/43",
"source": "vuln@ca.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/108483",
"source": "vuln@ca.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://seclists.org/bugtraq/2019/May/66",
"source": "vuln@ca.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "https://support.ca.com/us/product-content/recommended-reading/security-notices/CA20190523-01--security-notice-for-ca-risk-authentication-and-ca-strong-authentication.html",
"source": "vuln@ca.com",
"tags": [
"Vendor Advisory"
]
}
]
}