diff --git a/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json b/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json new file mode 100644 index 00000000000..cd384e63856 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-2fc7-57pg-9g23/GHSA-2fc7-57pg-9g23.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fc7-57pg-9g23", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2024-22337" + ], + "details": "IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279977.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22337" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279977" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7118642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5546-xcjq-x5xr/GHSA-5546-xcjq-x5xr.json b/advisories/unreviewed/2024/02/GHSA-5546-xcjq-x5xr/GHSA-5546-xcjq-x5xr.json new file mode 100644 index 00000000000..2d3bd12f185 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5546-xcjq-x5xr/GHSA-5546-xcjq-x5xr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5546-xcjq-x5xr", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2024-22336" + ], + "details": "IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279976.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22336" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279976" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7118642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6v8w-fxm4-82jx/GHSA-6v8w-fxm4-82jx.json b/advisories/unreviewed/2024/02/GHSA-6v8w-fxm4-82jx/GHSA-6v8w-fxm4-82jx.json new file mode 100644 index 00000000000..b1c25f4ee63 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6v8w-fxm4-82jx/GHSA-6v8w-fxm4-82jx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v8w-fxm4-82jx", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2022-41738" + ], + "details": "IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41738" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/237812" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7095312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9p5v-74f3-3rq6/GHSA-9p5v-74f3-3rq6.json b/advisories/unreviewed/2024/02/GHSA-9p5v-74f3-3rq6/GHSA-9p5v-74f3-3rq6.json new file mode 100644 index 00000000000..f6c61a11fc7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9p5v-74f3-3rq6/GHSA-9p5v-74f3-3rq6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p5v-74f3-3rq6", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2024-22335" + ], + "details": "IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 279975.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22335" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279975" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7118642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qffw-qrxh-5g73/GHSA-qffw-qrxh-5g73.json b/advisories/unreviewed/2024/02/GHSA-qffw-qrxh-5g73/GHSA-qffw-qrxh-5g73.json new file mode 100644 index 00000000000..27099c62ac3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qffw-qrxh-5g73/GHSA-qffw-qrxh-5g73.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qffw-qrxh-5g73", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2022-41737" + ], + "details": "IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. IBM X-Force ID: 237811.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41737" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/237811" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7095312" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rxj9-qx32-5mw6/GHSA-rxj9-qx32-5mw6.json b/advisories/unreviewed/2024/02/GHSA-rxj9-qx32-5mw6/GHSA-rxj9-qx32-5mw6.json new file mode 100644 index 00000000000..2bc73a9bebd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rxj9-qx32-5mw6/GHSA-rxj9-qx32-5mw6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxj9-qx32-5mw6", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2022-42443" + ], + "details": "An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42443" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/238535" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6967785" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json b/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json new file mode 100644 index 00000000000..5439fe62168 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w427-3xrr-2ccq/GHSA-w427-3xrr-2ccq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w427-3xrr-2ccq", + "modified": "2024-02-17T18:30:31Z", + "published": "2024-02-17T18:30:31Z", + "aliases": [ + "CVE-2023-50951" + ], + "details": "IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid authorization attempts. IBM X-Force ID: 275747.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50951" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/275747" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7118604" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-17T16:15:46Z" + } +} \ No newline at end of file