Show plain JSON{"id": "CVE-2019-4262", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Secondary", "source": "psirt@us.ibm.com", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 1.4, "exploitabilityScore": 3.9}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}]}, "published": "2019-09-26T15:15:10.320", "references": [{"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/160014", "tags": ["VDB Entry", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://www.ibm.com/support/pages/node/1074538", "tags": ["Patch", "Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/160014", "tags": ["VDB Entry", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.ibm.com/support/pages/node/1074538", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-918"}]}], "descriptions": [{"lang": "en", "value": "IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014."}, {"lang": "es", "value": "IBM QRadar SIEM versiones 7.2 y 7.3, es susceptible a una vulnerabilidad de tipo Server Side Request Forgery (SSRF). Esto puede permitir a un atacante no autenticado enviar peticiones no autorizadas desde el sistema QRadar, lo que puede conllevar a la enumeraci\u00f3n de la red o facilitar otros ataques. ID de IBM X-Force: 160014."}], "lastModified": "2024-11-21T04:43:23.740", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C48729A8-0CF2-486B-99E4-623C9C65F994", "versionEndExcluding": "7.2.8", "versionStartIncluding": "7.2.0"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1647C51C-71ED-491A-893F-D6998825F867", "versionEndExcluding": "7.3.2", "versionStartIncluding": "7.3.0"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC724282-7431-465E-8E60-4037121B8838"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73151221-C102-4425-9316-1EE4CAAB6531"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1E9DDCD-6D22-4175-94EF-D8A5457E7355"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p11:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35AB906F-43CD-4D54-8274-1FD551532E58"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p12:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1ADC75F0-B27E-4B15-B829-482FBA0063A5"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p13:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D015D670-8AEA-49A3-8D22-9E3009322EB0"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p14:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C18F3CC3-9BCF-4DE8-B7CA-59587D5E61F5"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p15:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E543BC0F-ADFB-4CF2-BC6C-90DC76BE3A95"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p16:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28CE650B-BE03-4EDF-BE27-2FA6657F7A52"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2356A4E6-561B-40CA-8348-B30D581B1E46"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "74509F3F-840E-48B8-88B1-EA4FFB90ACC3"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE7BD528-628F-4CA9-9FE8-8A79BDC97680"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26118C2B-78CC-4038-9DEA-7A9417029790"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29EBC1DD-6949-4B12-8CA5-EE2BCDB8C4C3"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F445D93-D482-4A74-810D-66D78CBCAFED"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C9F200C-ECC9-4D51-AFE7-E99C16D09148"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56B87CB5-0F77-4040-BB58-9DBF5723A4FD"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.3.2:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FECD03EF-2984-44F7-8DAD-BD3A608C2631"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.3.2:p1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43BD0A0A-349D-4C40-A1BF-78853DE8C72A"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.3.2:p2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8AE70A0F-E7BC-4DF7-A8A3-59F3975E27B8"}, {"criteria": "cpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.3.2:p3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "766E0831-A78D-4FD4-B830-1E818A7F1255"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}