diff --git a/advisories/unreviewed/2024/07/GHSA-93q5-fmhm-mp7p/GHSA-93q5-fmhm-mp7p.json b/advisories/unreviewed/2024/07/GHSA-93q5-fmhm-mp7p/GHSA-93q5-fmhm-mp7p.json new file mode 100644 index 00000000000..5ae6187e454 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-93q5-fmhm-mp7p/GHSA-93q5-fmhm-mp7p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93q5-fmhm-mp7p", + "modified": "2024-07-08T03:32:13Z", + "published": "2024-07-08T03:32:13Z", + "aliases": [ + "CVE-2024-38330" + ], + "details": "IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 295227.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38330" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/295227" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159615" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T02:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gmp6-hg9q-f8gw/GHSA-gmp6-hg9q-f8gw.json b/advisories/unreviewed/2024/07/GHSA-gmp6-hg9q-f8gw/GHSA-gmp6-hg9q-f8gw.json new file mode 100644 index 00000000000..78f1376fa2f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gmp6-hg9q-f8gw/GHSA-gmp6-hg9q-f8gw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmp6-hg9q-f8gw", + "modified": "2024-07-08T03:32:13Z", + "published": "2024-07-08T03:32:13Z", + "aliases": [ + "CVE-2024-31897" + ], + "details": "IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 288178.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31897" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/288178" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T03:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jr9f-3xg9-2j4f/GHSA-jr9f-3xg9-2j4f.json b/advisories/unreviewed/2024/07/GHSA-jr9f-3xg9-2j4f/GHSA-jr9f-3xg9-2j4f.json new file mode 100644 index 00000000000..6f036811dff --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jr9f-3xg9-2j4f/GHSA-jr9f-3xg9-2j4f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr9f-3xg9-2j4f", + "modified": "2024-07-08T03:32:11Z", + "published": "2024-07-08T03:32:11Z", + "aliases": [ + "CVE-2024-39723" + ], + "details": "IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39723" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/295935" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159333" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1299" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T01:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jvvp-q3wq-hcgm/GHSA-jvvp-q3wq-hcgm.json b/advisories/unreviewed/2024/07/GHSA-jvvp-q3wq-hcgm/GHSA-jvvp-q3wq-hcgm.json new file mode 100644 index 00000000000..96e47ceffa5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-jvvp-q3wq-hcgm/GHSA-jvvp-q3wq-hcgm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvvp-q3wq-hcgm", + "modified": "2024-07-08T03:32:13Z", + "published": "2024-07-08T03:32:13Z", + "aliases": [ + "CVE-2024-37528" + ], + "details": "IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 294293.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37528" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/294293" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7159332" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-08T03:15:02Z" + } +} \ No newline at end of file