2024-12-08 03:06:42 +00:00

162 lines
5.1 KiB
JSON

{
"id": "CVE-2017-1119",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2018-11-09T01:29:00.337",
"lastModified": "2024-11-21T03:21:21.570",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted request to cause an error message to be returned containing the full root path. An attacker could use this information to launch further attacks against the affected system. IBM X-Force ID: 121171."
},
{
"lang": "es",
"value": "IBM Marketing Operations 9.1.0, 9.1.2 y 10.1 pueden permitir que un atacante remoto obtenga informaci\u00f3n sensible. Un atacante puede enviar una petici\u00f3n especialmente manipulada para que se devuelva un mensaje de error que contenga la ruta de root completa. Un atacante podr\u00eda utilizar esta informaci\u00f3n para lanzar m\u00e1s ataques contra el sistema afectado. IBM X-Force ID: 121171."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "psirt@us.ibm.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"baseScore": 4.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:marketing_operations:*:*:*:*:*:*:*:*",
"versionStartIncluding": "9.1.0.0",
"versionEndIncluding": "9.1.0.12",
"matchCriteriaId": "45596737-8425-4E13-BEE8-3F58E6405393"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:marketing_operations:*:*:*:*:*:*:*:*",
"versionStartIncluding": "9.1.2.0",
"versionEndIncluding": "9.1.2.7",
"matchCriteriaId": "93137CAF-FF3A-4D92-9867-202EDBB95C95"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:marketing_operations:10.1:*:*:*:*:*:*:*",
"matchCriteriaId": "ED76351E-8D8B-43FA-985E-E80F3208F7A5"
}
]
}
]
}
],
"references": [
{
"url": "http://www.ibm.com/support/docview.wss?uid=ibm10738519",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/121171",
"source": "psirt@us.ibm.com",
"tags": [
"VDB Entry",
"Vendor Advisory"
]
},
{
"url": "http://www.ibm.com/support/docview.wss?uid=ibm10738519",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/121171",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"VDB Entry",
"Vendor Advisory"
]
}
]
}