From 1fa5fefc0e2a492995f9906db5d1fc83561d5342 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 24 Dec 2024 21:32:27 +0000 Subject: [PATCH] Publish Advisories GHSA-qcrh-jqxf-mgm4 GHSA-qj5p-g3mq-5m55 --- .../GHSA-qcrh-jqxf-mgm4.json | 7 +++- .../GHSA-qj5p-g3mq-5m55.json | 34 +++++++++++++++++++ 2 files changed, 40 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-qj5p-g3mq-5m55/GHSA-qj5p-g3mq-5m55.json diff --git a/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json b/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json index 8316dbde548..3d937acdfb4 100644 --- a/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json +++ b/advisories/unreviewed/2024/11/GHSA-qcrh-jqxf-mgm4/GHSA-qcrh-jqxf-mgm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qcrh-jqxf-mgm4", - "modified": "2024-11-18T06:30:36Z", + "modified": "2024-12-24T21:30:41Z", "published": "2024-11-18T06:30:36Z", "aliases": [ "CVE-2024-52926" @@ -22,10 +22,15 @@ { "type": "WEB", "url": "https://docs.delinea.com/online-help/privilege-manager/release-notes/12.0.2-combined.htm" + }, + { + "type": "WEB", + "url": "https://trust.delinea.com/?tcuUid=3be1a12c-97c9-431e-a51a-0c25da19ec86" } ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-276" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-qj5p-g3mq-5m55/GHSA-qj5p-g3mq-5m55.json b/advisories/unreviewed/2024/12/GHSA-qj5p-g3mq-5m55/GHSA-qj5p-g3mq-5m55.json new file mode 100644 index 00000000000..c77af03297a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qj5p-g3mq-5m55/GHSA-qj5p-g3mq-5m55.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj5p-g3mq-5m55", + "modified": "2024-12-24T21:30:41Z", + "published": "2024-12-24T21:30:41Z", + "aliases": [ + "CVE-2019-2483" + ], + "details": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-2483" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujan2019-5072801.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-24T19:15:05Z" + } +} \ No newline at end of file