From 3c329bf70b026a31acb0c8dc3fe6150a111e2521 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 7 Dec 2024 15:35:56 +0000 Subject: [PATCH] Publish Advisories GHSA-2qxc-962x-77hq GHSA-5f8v-qp5p-3gmv GHSA-cx5f-75fv-w3c7 GHSA-rm3m-4fg8-qg47 --- .../GHSA-2qxc-962x-77hq.json | 36 +++++++++++++++++++ .../GHSA-5f8v-qp5p-3gmv.json | 36 +++++++++++++++++++ .../GHSA-cx5f-75fv-w3c7.json | 36 +++++++++++++++++++ .../GHSA-rm3m-4fg8-qg47.json | 36 +++++++++++++++++++ 4 files changed, 144 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-2qxc-962x-77hq/GHSA-2qxc-962x-77hq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5f8v-qp5p-3gmv/GHSA-5f8v-qp5p-3gmv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rm3m-4fg8-qg47/GHSA-rm3m-4fg8-qg47.json diff --git a/advisories/unreviewed/2024/12/GHSA-2qxc-962x-77hq/GHSA-2qxc-962x-77hq.json b/advisories/unreviewed/2024/12/GHSA-2qxc-962x-77hq/GHSA-2qxc-962x-77hq.json new file mode 100644 index 00000000000..90c32b0156a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2qxc-962x-77hq/GHSA-2qxc-962x-77hq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qxc-962x-77hq", + "modified": "2024-12-07T15:34:10Z", + "published": "2024-12-07T15:34:10Z", + "aliases": [ + "CVE-2024-47107" + ], + "details": "IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47107" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178104" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-07T15:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5f8v-qp5p-3gmv/GHSA-5f8v-qp5p-3gmv.json b/advisories/unreviewed/2024/12/GHSA-5f8v-qp5p-3gmv/GHSA-5f8v-qp5p-3gmv.json new file mode 100644 index 00000000000..51d3630453f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5f8v-qp5p-3gmv/GHSA-5f8v-qp5p-3gmv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f8v-qp5p-3gmv", + "modified": "2024-12-07T15:34:10Z", + "published": "2024-12-07T15:34:10Z", + "aliases": [ + "CVE-2024-37071" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37071" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175940" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-07T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json b/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json new file mode 100644 index 00000000000..030872ff889 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cx5f-75fv-w3c7/GHSA-cx5f-75fv-w3c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx5f-75fv-w3c7", + "modified": "2024-12-07T15:34:10Z", + "published": "2024-12-07T15:34:10Z", + "aliases": [ + "CVE-2024-41762" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41762" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7175946" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-789" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-07T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rm3m-4fg8-qg47/GHSA-rm3m-4fg8-qg47.json b/advisories/unreviewed/2024/12/GHSA-rm3m-4fg8-qg47/GHSA-rm3m-4fg8-qg47.json new file mode 100644 index 00000000000..6ac0503ff7c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rm3m-4fg8-qg47/GHSA-rm3m-4fg8-qg47.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm3m-4fg8-qg47", + "modified": "2024-12-07T15:34:10Z", + "published": "2024-12-07T15:34:10Z", + "aliases": [ + "CVE-2024-47115" + ], + "details": "IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47115" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-07T13:19:14Z" + } +} \ No newline at end of file