From 4fb0ebfe2b285cfce2254c8f51dcb3065e529bcf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Jul 2023 03:31:45 +0000 Subject: [PATCH] Publish Advisories GHSA-377h-vgg5-642q GHSA-37c2-5chg-wwj7 GHSA-3f53-3vgw-49w5 GHSA-4m3h-hm42-fpq8 GHSA-4qc6-2rm7-vx7r GHSA-4qhp-mwrw-89jx GHSA-55fw-854f-62mp GHSA-5cgp-98vf-r77v GHSA-735x-m7jj-qwvp GHSA-7775-vpxf-hr38 GHSA-7f43-782r-rjgv GHSA-fj2m-7r3q-j27x GHSA-gc4p-x49g-c3h3 GHSA-h3cv-ph2c-8x5w GHSA-hp7v-3j27-4q36 GHSA-hxrw-m55w-9qx8 GHSA-j46x-wj3p-r6qg GHSA-jhwx-fm67-385p GHSA-jjrx-x5mm-p728 GHSA-mq9c-rx7q-5jph GHSA-pgvh-wr92-g752 GHSA-pr3p-hv9q-44xx GHSA-vr8f-3gcr-v88v GHSA-xhp3-g75g-8f9j --- .../GHSA-377h-vgg5-642q.json | 42 ++++++++++++++++ .../GHSA-37c2-5chg-wwj7.json | 42 ++++++++++++++++ .../GHSA-3f53-3vgw-49w5.json | 42 ++++++++++++++++ .../GHSA-4m3h-hm42-fpq8.json | 42 ++++++++++++++++ .../GHSA-4qc6-2rm7-vx7r.json | 39 +++++++++++++++ .../GHSA-4qhp-mwrw-89jx.json | 42 ++++++++++++++++ .../GHSA-55fw-854f-62mp.json | 42 ++++++++++++++++ .../GHSA-5cgp-98vf-r77v.json | 42 ++++++++++++++++ .../GHSA-735x-m7jj-qwvp.json | 42 ++++++++++++++++ .../GHSA-7775-vpxf-hr38.json | 42 ++++++++++++++++ .../GHSA-7f43-782r-rjgv.json | 4 +- .../GHSA-fj2m-7r3q-j27x.json | 42 ++++++++++++++++ .../GHSA-gc4p-x49g-c3h3.json | 39 +++++++++++++++ .../GHSA-h3cv-ph2c-8x5w.json | 39 +++++++++++++++ .../GHSA-hp7v-3j27-4q36.json | 42 ++++++++++++++++ .../GHSA-hxrw-m55w-9qx8.json | 50 +++++++++++++++++++ .../GHSA-j46x-wj3p-r6qg.json | 42 ++++++++++++++++ .../GHSA-jhwx-fm67-385p.json | 42 ++++++++++++++++ .../GHSA-jjrx-x5mm-p728.json | 50 +++++++++++++++++++ .../GHSA-mq9c-rx7q-5jph.json | 42 ++++++++++++++++ .../GHSA-pgvh-wr92-g752.json | 42 ++++++++++++++++ .../GHSA-pr3p-hv9q-44xx.json | 42 ++++++++++++++++ .../GHSA-vr8f-3gcr-v88v.json | 42 ++++++++++++++++ .../GHSA-xhp3-g75g-8f9j.json | 42 ++++++++++++++++ 24 files changed, 975 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2023/07/GHSA-377h-vgg5-642q/GHSA-377h-vgg5-642q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4m3h-hm42-fpq8/GHSA-4m3h-hm42-fpq8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4qc6-2rm7-vx7r/GHSA-4qc6-2rm7-vx7r.json create mode 100644 advisories/unreviewed/2023/07/GHSA-4qhp-mwrw-89jx/GHSA-4qhp-mwrw-89jx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-55fw-854f-62mp/GHSA-55fw-854f-62mp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5cgp-98vf-r77v/GHSA-5cgp-98vf-r77v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-735x-m7jj-qwvp/GHSA-735x-m7jj-qwvp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7775-vpxf-hr38/GHSA-7775-vpxf-hr38.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json create mode 100644 advisories/unreviewed/2023/07/GHSA-gc4p-x49g-c3h3/GHSA-gc4p-x49g-c3h3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h3cv-ph2c-8x5w/GHSA-h3cv-ph2c-8x5w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hp7v-3j27-4q36/GHSA-hp7v-3j27-4q36.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hxrw-m55w-9qx8/GHSA-hxrw-m55w-9qx8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j46x-wj3p-r6qg/GHSA-j46x-wj3p-r6qg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jjrx-x5mm-p728/GHSA-jjrx-x5mm-p728.json create mode 100644 advisories/unreviewed/2023/07/GHSA-mq9c-rx7q-5jph/GHSA-mq9c-rx7q-5jph.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pgvh-wr92-g752/GHSA-pgvh-wr92-g752.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pr3p-hv9q-44xx/GHSA-pr3p-hv9q-44xx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vr8f-3gcr-v88v/GHSA-vr8f-3gcr-v88v.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xhp3-g75g-8f9j/GHSA-xhp3-g75g-8f9j.json diff --git a/advisories/unreviewed/2023/07/GHSA-377h-vgg5-642q/GHSA-377h-vgg5-642q.json b/advisories/unreviewed/2023/07/GHSA-377h-vgg5-642q/GHSA-377h-vgg5-642q.json new file mode 100644 index 00000000000..18899ead021 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-377h-vgg5-642q/GHSA-377h-vgg5-642q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-377h-vgg5-642q", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36921" + ], + "details": "SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36921" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3348145" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json b/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json new file mode 100644 index 00000000000..5761c175ead --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-37c2-5chg-wwj7/GHSA-37c2-5chg-wwj7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37c2-5chg-wwj7", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-35874" + ], + "details": "SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper authentication checks for functionalities that require user identity. An attacker can perform malicious actions over the network, extending the scope of impact, causing a limited impact on confidentiality, integrity and availability.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35874" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3318850" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json b/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json new file mode 100644 index 00000000000..f4504acde35 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3f53-3vgw-49w5/GHSA-3f53-3vgw-49w5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f53-3vgw-49w5", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36919" + ], + "details": "In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response header is not implemented, allowing an unauthenticated attacker to obtain referrer details, resulting in information disclosure.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36919" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3326769" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4m3h-hm42-fpq8/GHSA-4m3h-hm42-fpq8.json b/advisories/unreviewed/2023/07/GHSA-4m3h-hm42-fpq8/GHSA-4m3h-hm42-fpq8.json new file mode 100644 index 00000000000..e2788bec14f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4m3h-hm42-fpq8/GHSA-4m3h-hm42-fpq8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m3h-hm42-fpq8", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36917" + ], + "details": "SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could lead to an attacker to completely takeover a victim’s account.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36917" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3320702" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4qc6-2rm7-vx7r/GHSA-4qc6-2rm7-vx7r.json b/advisories/unreviewed/2023/07/GHSA-4qc6-2rm7-vx7r/GHSA-4qc6-2rm7-vx7r.json new file mode 100644 index 00000000000..41daa28fe1f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4qc6-2rm7-vx7r/GHSA-4qc6-2rm7-vx7r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qc6-2rm7-vx7r", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-37191" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37191" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-37191/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://reference3.example.com/index.php?menu=faxnew" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-4qhp-mwrw-89jx/GHSA-4qhp-mwrw-89jx.json b/advisories/unreviewed/2023/07/GHSA-4qhp-mwrw-89jx/GHSA-4qhp-mwrw-89jx.json new file mode 100644 index 00000000000..3b2e820cfeb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-4qhp-mwrw-89jx/GHSA-4qhp-mwrw-89jx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qhp-mwrw-89jx", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36922" + ], + "details": "Due to programming error in function module or report, SAP NetWeaver ABAP (IS-OIL) - versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806, 807, allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36922" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3350297" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-55fw-854f-62mp/GHSA-55fw-854f-62mp.json b/advisories/unreviewed/2023/07/GHSA-55fw-854f-62mp/GHSA-55fw-854f-62mp.json new file mode 100644 index 00000000000..8f5c3cbee7c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-55fw-854f-62mp/GHSA-55fw-854f-62mp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55fw-854f-62mp", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-35873" + ], + "details": "The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35873" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3343547" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5cgp-98vf-r77v/GHSA-5cgp-98vf-r77v.json b/advisories/unreviewed/2023/07/GHSA-5cgp-98vf-r77v/GHSA-5cgp-98vf-r77v.json new file mode 100644 index 00000000000..aa210a3c558 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5cgp-98vf-r77v/GHSA-5cgp-98vf-r77v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cgp-98vf-r77v", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36918" + ], + "details": "In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36918" + }, + { + "type": "WEB", + "url": "https://launchpad.support.sap.com/#/notes/3326769" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-735x-m7jj-qwvp/GHSA-735x-m7jj-qwvp.json b/advisories/unreviewed/2023/07/GHSA-735x-m7jj-qwvp/GHSA-735x-m7jj-qwvp.json new file mode 100644 index 00000000000..6bab712ef0f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-735x-m7jj-qwvp/GHSA-735x-m7jj-qwvp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-735x-m7jj-qwvp", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-31405" + ], + "details": "SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any information or any effect on availability.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31405" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3324732" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7775-vpxf-hr38/GHSA-7775-vpxf-hr38.json b/advisories/unreviewed/2023/07/GHSA-7775-vpxf-hr38/GHSA-7775-vpxf-hr38.json new file mode 100644 index 00000000000..9e3fc5884e3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7775-vpxf-hr38/GHSA-7775-vpxf-hr38.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7775-vpxf-hr38", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-35872" + ], + "details": "The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35872" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3343564" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json b/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json index 6c2658bb588..d978615243a 100644 --- a/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json +++ b/advisories/unreviewed/2023/07/GHSA-7f43-782r-rjgv/GHSA-7f43-782r-rjgv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f43-782r-rjgv", - "modified": "2023-07-05T15:30:25Z", + "modified": "2023-07-11T03:30:30Z", "published": "2023-07-05T15:30:25Z", "aliases": [ "CVE-2023-35973" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json b/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json new file mode 100644 index 00000000000..36b54aa2213 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fj2m-7r3q-j27x/GHSA-fj2m-7r3q-j27x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj2m-7r3q-j27x", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-33990" + ], + "details": "SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an attacker to perform a Denial of Service. Further, an attacker might be able to modify sensitive data in shared memory objects.This issue only affects SAP SQL Anywhere on Windows. Other platforms are not impacted.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33990" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3331029" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-gc4p-x49g-c3h3/GHSA-gc4p-x49g-c3h3.json b/advisories/unreviewed/2023/07/GHSA-gc4p-x49g-c3h3/GHSA-gc4p-x49g-c3h3.json new file mode 100644 index 00000000000..94f331a5c16 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-gc4p-x49g-c3h3/GHSA-gc4p-x49g-c3h3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc4p-x49g-c3h3", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-37190" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37190" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-37190/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://reference2.example.com/index.php?menu=grouplist" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h3cv-ph2c-8x5w/GHSA-h3cv-ph2c-8x5w.json b/advisories/unreviewed/2023/07/GHSA-h3cv-ph2c-8x5w/GHSA-h3cv-ph2c-8x5w.json new file mode 100644 index 00000000000..c32cf744dfd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h3cv-ph2c-8x5w/GHSA-h3cv-ph2c-8x5w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3cv-ph2c-8x5w", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-37189" + ], + "details": "A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37189" + }, + { + "type": "WEB", + "url": "https://github.com/sahiloj/CVE-2023-37189/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://reference1.example.com/index.php?menu=billing_rates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hp7v-3j27-4q36/GHSA-hp7v-3j27-4q36.json b/advisories/unreviewed/2023/07/GHSA-hp7v-3j27-4q36/GHSA-hp7v-3j27-4q36.json new file mode 100644 index 00000000000..864d0ae7e97 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hp7v-3j27-4q36/GHSA-hp7v-3j27-4q36.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp7v-3j27-4q36", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-33987" + ], + "details": "An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33987" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3233899" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hxrw-m55w-9qx8/GHSA-hxrw-m55w-9qx8.json b/advisories/unreviewed/2023/07/GHSA-hxrw-m55w-9qx8/GHSA-hxrw-m55w-9qx8.json new file mode 100644 index 00000000000..abcb8e70107 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hxrw-m55w-9qx8/GHSA-hxrw-m55w-9qx8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxrw-m55w-9qx8", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-2079" + ], + "details": "The \"Buy Me a Coffee – Button and Widget Plugin\" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to update the plugins settings, via a forged request granted the attacker can trick a site's administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2079" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buymeacoffee/trunk/admin/class-buy-me-a-coffee-admin.php?rev=2816542" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buymeacoffee/trunk/includes/class-buy-me-a-coffee.php?rev=2319979#L162" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2935565%40buymeacoffee&new=2935565%40buymeacoffee&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6309258e-e4fc-4edf-a771-2d82a9a85a5c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j46x-wj3p-r6qg/GHSA-j46x-wj3p-r6qg.json b/advisories/unreviewed/2023/07/GHSA-j46x-wj3p-r6qg/GHSA-j46x-wj3p-r6qg.json new file mode 100644 index 00000000000..12597620ddf --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j46x-wj3p-r6qg/GHSA-j46x-wj3p-r6qg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j46x-wj3p-r6qg", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36925" + ], + "details": "SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36925" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3352058" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json b/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json new file mode 100644 index 00000000000..96408e394b9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jhwx-fm67-385p/GHSA-jhwx-fm67-385p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhwx-fm67-385p", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-35870" + ], + "details": "When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35870" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3341211" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jjrx-x5mm-p728/GHSA-jjrx-x5mm-p728.json b/advisories/unreviewed/2023/07/GHSA-jjrx-x5mm-p728/GHSA-jjrx-x5mm-p728.json new file mode 100644 index 00000000000..dfbf5e428f8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jjrx-x5mm-p728/GHSA-jjrx-x5mm-p728.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjrx-x5mm-p728", + "modified": "2023-07-11T03:30:30Z", + "published": "2023-07-11T03:30:30Z", + "aliases": [ + "CVE-2023-2078" + ], + "details": "The \"Buy Me a Coffee – Button and Widget Plugin\" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to update the plugins settings. CVE-2023-25030 may be a duplicate of this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2078" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buymeacoffee/trunk/admin/class-buy-me-a-coffee-admin.php?rev=2816542" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buymeacoffee/trunk/includes/class-buy-me-a-coffee.php?rev=2319979#L162" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2935565%40buymeacoffee&new=2935565%40buymeacoffee&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c1c218c6-1599-4dc9-846f-e0ef74821488?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-mq9c-rx7q-5jph/GHSA-mq9c-rx7q-5jph.json b/advisories/unreviewed/2023/07/GHSA-mq9c-rx7q-5jph/GHSA-mq9c-rx7q-5jph.json new file mode 100644 index 00000000000..2cf22f14ec7 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mq9c-rx7q-5jph/GHSA-mq9c-rx7q-5jph.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq9c-rx7q-5jph", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-35871" + ], + "details": "The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, has a vulnerability that can be exploited by an unauthenticated attacker to cause memory corruption through logical errors in memory management this may leads to information disclosure or system crashes, which can have low impact on confidentiality and high impact on the integrity and availability of the system.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35871" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3340735" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pgvh-wr92-g752/GHSA-pgvh-wr92-g752.json b/advisories/unreviewed/2023/07/GHSA-pgvh-wr92-g752/GHSA-pgvh-wr92-g752.json new file mode 100644 index 00000000000..4dfbaf221d0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pgvh-wr92-g752/GHSA-pgvh-wr92-g752.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgvh-wr92-g752", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-33992" + ], + "details": "The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33992" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3088078" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pr3p-hv9q-44xx/GHSA-pr3p-hv9q-44xx.json b/advisories/unreviewed/2023/07/GHSA-pr3p-hv9q-44xx/GHSA-pr3p-hv9q-44xx.json new file mode 100644 index 00000000000..665221d9721 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pr3p-hv9q-44xx/GHSA-pr3p-hv9q-44xx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr3p-hv9q-44xx", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-36924" + ], + "details": "While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36924" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3351410" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vr8f-3gcr-v88v/GHSA-vr8f-3gcr-v88v.json b/advisories/unreviewed/2023/07/GHSA-vr8f-3gcr-v88v/GHSA-vr8f-3gcr-v88v.json new file mode 100644 index 00000000000..60d01d7bcd1 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vr8f-3gcr-v88v/GHSA-vr8f-3gcr-v88v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr8f-3gcr-v88v", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-33988" + ], + "details": "In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-XSS-Protection response headers are not implemented, allowing an unauthenticated attacker to attempt reflected cross-site scripting, which could result in disclosure or modification of information.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33988" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3326769" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xhp3-g75g-8f9j/GHSA-xhp3-g75g-8f9j.json b/advisories/unreviewed/2023/07/GHSA-xhp3-g75g-8f9j/GHSA-xhp3-g75g-8f9j.json new file mode 100644 index 00000000000..078733e926f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xhp3-g75g-8f9j/GHSA-xhp3-g75g-8f9j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhp3-g75g-8f9j", + "modified": "2023-07-11T03:30:31Z", + "published": "2023-07-11T03:30:31Z", + "aliases": [ + "CVE-2023-33989" + ], + "details": "An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33989" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3331376" + }, + { + "type": "WEB", + "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file