diff --git a/advisories/unreviewed/2024/08/GHSA-45m2-f9mw-223r/GHSA-45m2-f9mw-223r.json b/advisories/unreviewed/2024/08/GHSA-45m2-f9mw-223r/GHSA-45m2-f9mw-223r.json new file mode 100644 index 00000000000..652ecfbaba7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-45m2-f9mw-223r/GHSA-45m2-f9mw-223r.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45m2-f9mw-223r", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-41734" + ], + "details": "Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41734" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3494349" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4cwg-vmj9-q8qf/GHSA-4cwg-vmj9-q8qf.json b/advisories/unreviewed/2024/08/GHSA-4cwg-vmj9-q8qf/GHSA-4cwg-vmj9-q8qf.json new file mode 100644 index 00000000000..49db3750c69 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4cwg-vmj9-q8qf/GHSA-4cwg-vmj9-q8qf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cwg-vmj9-q8qf", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-39591" + ], + "details": "SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39591" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3477423" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4x4m-ghmx-6q9w/GHSA-4x4m-ghmx-6q9w.json b/advisories/unreviewed/2024/08/GHSA-4x4m-ghmx-6q9w/GHSA-4x4m-ghmx-6q9w.json new file mode 100644 index 00000000000..a06631522c7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4x4m-ghmx-6q9w/GHSA-4x4m-ghmx-6q9w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x4m-ghmx-6q9w", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41733" + ], + "details": "In SAP Commerce, valid user accounts can be\nidentified during the customer registration and login processes. This allows a\npotential attacker to learn if a given e-mail is used for an account, but does\nnot grant access to any customer data beyond this knowledge. The attacker must\nalready know the e-mail that they wish to test for. The impact on\nconfidentiality therefore is low and no impact to integrity or availability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41733" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3471450" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-58h5-p6fc-6jg8/GHSA-58h5-p6fc-6jg8.json b/advisories/unreviewed/2024/08/GHSA-58h5-p6fc-6jg8/GHSA-58h5-p6fc-6jg8.json new file mode 100644 index 00000000000..bb834699f0e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-58h5-p6fc-6jg8/GHSA-58h5-p6fc-6jg8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58h5-p6fc-6jg8", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-6823" + ], + "details": "The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6823" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-assistant/trunk/includes/class-mla-settings.php#L32" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3133909" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/media-library-assistant/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9a446fe7-c97a-436e-b494-b924e6518297?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5hhx-v396-wch6/GHSA-5hhx-v396-wch6.json b/advisories/unreviewed/2024/08/GHSA-5hhx-v396-wch6/GHSA-5hhx-v396-wch6.json new file mode 100644 index 00000000000..b4dc9bb6932 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5hhx-v396-wch6/GHSA-5hhx-v396-wch6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hhx-v396-wch6", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41732" + ], + "details": "SAP NetWeaver Application Server ABAP allows\n an unauthenticated attacker to craft a URL link that could bypass allowlist\n controls. Depending on the web applications provided by this server, the\n attacker might inject CSS code or links into the web application that could\n allow the attacker to read or modify information. There is no impact on\n availability of application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41732" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3468102" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6xm3-rj4q-c353/GHSA-6xm3-rj4q-c353.json b/advisories/unreviewed/2024/08/GHSA-6xm3-rj4q-c353/GHSA-6xm3-rj4q-c353.json new file mode 100644 index 00000000000..96690d163f9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6xm3-rj4q-c353/GHSA-6xm3-rj4q-c353.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xm3-rj4q-c353", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41736" + ], + "details": "Under certain conditions SAP Permit to Work\nallows an authenticated attacker to access information which would otherwise be\nrestricted causing low impact on the confidentiality of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41736" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3475427" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7m3q-23p4-mw4v/GHSA-7m3q-23p4-mw4v.json b/advisories/unreviewed/2024/08/GHSA-7m3q-23p4-mw4v/GHSA-7m3q-23p4-mw4v.json new file mode 100644 index 00000000000..6bebe239406 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7m3q-23p4-mw4v/GHSA-7m3q-23p4-mw4v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m3q-23p4-mw4v", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-33003" + ], + "details": "Some OCC API endpoints in SAP Commerce Cloud\nallows Personally Identifiable Information (PII) data, such as passwords, email\naddresses, mobile numbers, coupon codes, and voucher codes, to be included in\nthe request URL as query or path parameters. On successful exploitation, this\ncould lead to a High impact on confidentiality and integrity of the\napplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33003" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3459935" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json b/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json new file mode 100644 index 00000000000..527356fd507 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q89-2pq5-3fpq", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-7092" + ], + "details": "The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘no_more_items_text’ parameter in all versions up to, and including, 5.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7092" + }, + { + "type": "WEB", + "url": "https://essential-addons.com/changelog" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/trunk/includes/Elements/Filterable_Gallery.php#L3879" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/trunk/includes/Elements/Filterable_Gallery.php#L3900" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3134194" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/essential-addons-for-elementor-lite/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/718c60c1-6117-4959-a907-d0ef457f7185?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T05:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8f2v-7rj4-gq54/GHSA-8f2v-7rj4-gq54.json b/advisories/unreviewed/2024/08/GHSA-8f2v-7rj4-gq54/GHSA-8f2v-7rj4-gq54.json new file mode 100644 index 00000000000..69c3abf6518 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8f2v-7rj4-gq54/GHSA-8f2v-7rj4-gq54.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f2v-7rj4-gq54", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41735" + ], + "details": "SAP Commerce Backoffice does not sufficiently\nencode user-controlled inputs, resulting in Cross-Site Scripting (XSS)\nvulnerability causing low impact on confidentiality and integrity of the\napplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41735" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3483256" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9gx3-jqv2-vphr/GHSA-9gx3-jqv2-vphr.json b/advisories/unreviewed/2024/08/GHSA-9gx3-jqv2-vphr/GHSA-9gx3-jqv2-vphr.json new file mode 100644 index 00000000000..95f15fc2032 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9gx3-jqv2-vphr/GHSA-9gx3-jqv2-vphr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gx3-jqv2-vphr", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-42377" + ], + "details": "SAP shared service framework allows an\nauthenticated non-administrative user to call a remote-enabled function, which\nwill allow them to insert value entries into a non-sensitive table, causing low\nimpact on integrity of the application", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42377" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3474590" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json b/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json new file mode 100644 index 00000000000..2142f37d713 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ch8j-4g5p-qvwx/GHSA-ch8j-4g5p-qvwx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch8j-4g5p-qvwx", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-6724" + ], + "details": "The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6724" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0cb3158a-263d-4c4a-8029-62b453c281cb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T06:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json b/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json new file mode 100644 index 00000000000..7664eab7f0c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f2gw-3cqw-xmj7/GHSA-f2gw-3cqw-xmj7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2gw-3cqw-xmj7", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-28166" + ], + "details": "SAP BusinessObjects Business Intelligence\n Platform allows an authenticated attacker to upload malicious code over the\n network, that could be executed by the application. On successful\n exploitation, the attacker can cause a low impact on the Integrity of the\n application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28166" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3433545" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f3rg-6v2h-rjpj/GHSA-f3rg-6v2h-rjpj.json b/advisories/unreviewed/2024/08/GHSA-f3rg-6v2h-rjpj/GHSA-f3rg-6v2h-rjpj.json new file mode 100644 index 00000000000..df77c735d77 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f3rg-6v2h-rjpj/GHSA-f3rg-6v2h-rjpj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3rg-6v2h-rjpj", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-33005" + ], + "details": "Due to the missing authorization checks in the\nlocal systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application\nServer (ABAP and Java), and SAP Content Server can impersonate other users and\nmay perform some unintended actions. This could lead to a low impact on\nconfidentiality and a high impact on the integrity and availability of the\napplications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33005" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3438085" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fg4w-vj95-g2c7/GHSA-fg4w-vj95-g2c7.json b/advisories/unreviewed/2024/08/GHSA-fg4w-vj95-g2c7/GHSA-fg4w-vj95-g2c7.json new file mode 100644 index 00000000000..3429c63f5a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fg4w-vj95-g2c7/GHSA-fg4w-vj95-g2c7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg4w-vj95-g2c7", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41730" + ], + "details": "In SAP BusinessObjects Business Intelligence\nPlatform, if Single Signed On is enabled on Enterprise authentication, an\nunauthorized user can get a logon token using a REST endpoint. The attacker can\nfully compromise the system resulting in High impact on confidentiality,\nintegrity and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41730" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3479478" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gf9h-r59m-m9g4/GHSA-gf9h-r59m-m9g4.json b/advisories/unreviewed/2024/08/GHSA-gf9h-r59m-m9g4/GHSA-gf9h-r59m-m9g4.json new file mode 100644 index 00000000000..41bb8bdea41 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gf9h-r59m-m9g4/GHSA-gf9h-r59m-m9g4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf9h-r59m-m9g4", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-42375" + ], + "details": "SAP BusinessObjects Business Intelligence\n Platform allows an authenticated attacker to upload malicious code over the\n network, that could be executed by the application. On successful exploitation,\n the attacker can cause a low impact on the Integrity of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42375" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3433545" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hh65-pfmq-9x2q/GHSA-hh65-pfmq-9x2q.json b/advisories/unreviewed/2024/08/GHSA-hh65-pfmq-9x2q/GHSA-hh65-pfmq-9x2q.json new file mode 100644 index 00000000000..a57c65175a6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hh65-pfmq-9x2q/GHSA-hh65-pfmq-9x2q.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh65-pfmq-9x2q", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-7247" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Gallery and Countdown widgets in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7247" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/assets/js/bdt-uikit.js#L4223" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/assets/js/ep-scripts.js#L514" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/assets/js/ep-scripts.js#L576" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3133714" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3133714/#file1110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3130355%40bdthemes-element-pack-lite&new=3130355%40bdthemes-element-pack-lite&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/bdthemes-element-pack-lite/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86068c50-2f24-4af9-a20f-704d52e98ce2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hvr2-rrr8-q8r2/GHSA-hvr2-rrr8-q8r2.json b/advisories/unreviewed/2024/08/GHSA-hvr2-rrr8-q8r2/GHSA-hvr2-rrr8-q8r2.json new file mode 100644 index 00000000000..1fddde4a959 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hvr2-rrr8-q8r2/GHSA-hvr2-rrr8-q8r2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvr2-rrr8-q8r2", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41731" + ], + "details": "SAP BusinessObjects Business Intelligence\nPlatform allows an authenticated attacker to upload malicious code over the\nnetwork, that could be executed by the application. On successful exploitation,\nthe attacker can cause a low impact on the Integrity of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41731" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3433545" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qq3q-q2pr-3vj8/GHSA-qq3q-q2pr-3vj8.json b/advisories/unreviewed/2024/08/GHSA-qq3q-q2pr-3vj8/GHSA-qq3q-q2pr-3vj8.json new file mode 100644 index 00000000000..e4d140b510b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qq3q-q2pr-3vj8/GHSA-qq3q-q2pr-3vj8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq3q-q2pr-3vj8", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-42373" + ], + "details": "SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to delete non-sensitive report variants that are typically restricted, causing minimal impact on the integrity of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42373" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3479293" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T05:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r82q-4998-95r2/GHSA-r82q-4998-95r2.json b/advisories/unreviewed/2024/08/GHSA-r82q-4998-95r2/GHSA-r82q-4998-95r2.json new file mode 100644 index 00000000000..3288f4c1e03 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r82q-4998-95r2/GHSA-r82q-4998-95r2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r82q-4998-95r2", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-42374" + ], + "details": "BEx Web Java Runtime Export Web Service does not\nsufficiently validate an XML document accepted from an untrusted source. An\nattacker can retrieve information from the SAP ADS system and exhaust the\nnumber of XMLForm service which makes the SAP ADS rendering (PDF creation)\nunavailable. This affects the confidentiality and availability of the\napplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42374" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3485284" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-91" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rw5c-82rr-mprm/GHSA-rw5c-82rr-mprm.json b/advisories/unreviewed/2024/08/GHSA-rw5c-82rr-mprm/GHSA-rw5c-82rr-mprm.json new file mode 100644 index 00000000000..84cf67af9e2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rw5c-82rr-mprm/GHSA-rw5c-82rr-mprm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw5c-82rr-mprm", + "modified": "2024-08-13T06:30:48Z", + "published": "2024-08-13T06:30:48Z", + "aliases": [ + "CVE-2024-42376" + ], + "details": "SAP Shared Service Framework does not perform necessary\nauthorization check for an authenticated user, resulting in escalation of\nprivileges. On successful exploitation, an attacker can cause a high impact on\nconfidentiality of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42376" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3474590" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xxmg-wvh2-q23q/GHSA-xxmg-wvh2-q23q.json b/advisories/unreviewed/2024/08/GHSA-xxmg-wvh2-q23q/GHSA-xxmg-wvh2-q23q.json new file mode 100644 index 00000000000..3ec0f249621 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xxmg-wvh2-q23q/GHSA-xxmg-wvh2-q23q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxmg-wvh2-q23q", + "modified": "2024-08-13T06:30:47Z", + "published": "2024-08-13T06:30:47Z", + "aliases": [ + "CVE-2024-41737" + ], + "details": "SAP CRM ABAP (Insights\nManagement) allows an authenticated attacker to enumerate HTTP endpoints in the\ninternal network by specially crafting HTTP requests. On successful\nexploitation this can result in information disclosure. It has no impact on\nintegrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41737" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3487537" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T04:15:10Z" + } +} \ No newline at end of file