From e3e17726c2fb9a1db32deea5b56452cc445af4b3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 May 2025 03:33:18 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-rgj6-mpw9-qm58.json | 8 +++- .../GHSA-363m-3jp4-qg24.json | 4 +- .../GHSA-h9pr-qr4v-f87f.json | 4 +- .../GHSA-mqx4-g9cq-jvc6.json | 4 +- .../GHSA-pgf5-9895-3ph9.json | 4 +- .../GHSA-w5wq-cvfc-3r8g.json | 4 +- .../GHSA-wv8p-qvw7-q865.json | 4 +- .../GHSA-3xp5-7h92-mqvv.json | 4 +- .../GHSA-97gr-9g44-39q4.json | 4 +- .../GHSA-9fcr-j456-qxxg.json | 4 +- .../GHSA-mgqc-jwxc-fx8x.json | 4 +- .../GHSA-qp28-67v3-65qc.json | 4 +- .../GHSA-rgw4-v387-9jvw.json | 4 +- .../GHSA-w8j6-vhx2-7qvh.json | 4 +- .../GHSA-9cxr-86mw-8jw2.json | 6 ++- .../GHSA-3xfw-592p-fx76.json | 40 +++++++++++++++++ .../GHSA-5x6q-c4xg-h54m.json | 40 +++++++++++++++++ .../GHSA-73c9-m6v4-gr66.json | 40 +++++++++++++++++ .../GHSA-7r36-ppxr-258g.json | 40 +++++++++++++++++ .../GHSA-94gr-9qc8-c44p.json | 40 +++++++++++++++++ .../GHSA-c382-rxwx-qqcr.json | 40 +++++++++++++++++ .../GHSA-c588-wghg-39q4.json | 40 +++++++++++++++++ .../GHSA-c9j5-3rxr-ch9p.json | 40 +++++++++++++++++ .../GHSA-cww2-f4cr-g22m.json | 40 +++++++++++++++++ .../GHSA-f2w6-r722-5fr8.json | 6 ++- .../GHSA-fffx-47hq-rh2f.json | 40 +++++++++++++++++ .../GHSA-fxhc-gwf9-69jh.json | 40 +++++++++++++++++ .../GHSA-j2cw-3q46-v5jg.json | 40 +++++++++++++++++ .../GHSA-q59c-g8h6-83g2.json | 40 +++++++++++++++++ .../GHSA-rgq9-rg7j-xm4x.json | 40 +++++++++++++++++ .../GHSA-v2rg-3wmw-65x9.json | 40 +++++++++++++++++ .../GHSA-wv5q-x2gm-xf7j.json | 44 +++++++++++++++++++ .../GHSA-wwrf-457v-6cqw.json | 40 +++++++++++++++++ .../GHSA-x226-jp3j-r3hc.json | 40 +++++++++++++++++ .../GHSA-xh3w-9cjp-3cf8.json | 40 +++++++++++++++++ .../GHSA-xrxq-x8xp-9x7h.json | 40 +++++++++++++++++ .../GHSA-xvx6-286h-35qm.json | 40 +++++++++++++++++ 37 files changed, 898 insertions(+), 18 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-3xfw-592p-fx76/GHSA-3xfw-592p-fx76.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5x6q-c4xg-h54m/GHSA-5x6q-c4xg-h54m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-73c9-m6v4-gr66/GHSA-73c9-m6v4-gr66.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7r36-ppxr-258g/GHSA-7r36-ppxr-258g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-94gr-9qc8-c44p/GHSA-94gr-9qc8-c44p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c382-rxwx-qqcr/GHSA-c382-rxwx-qqcr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c588-wghg-39q4/GHSA-c588-wghg-39q4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c9j5-3rxr-ch9p/GHSA-c9j5-3rxr-ch9p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cww2-f4cr-g22m/GHSA-cww2-f4cr-g22m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fffx-47hq-rh2f/GHSA-fffx-47hq-rh2f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fxhc-gwf9-69jh/GHSA-fxhc-gwf9-69jh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j2cw-3q46-v5jg/GHSA-j2cw-3q46-v5jg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q59c-g8h6-83g2/GHSA-q59c-g8h6-83g2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v2rg-3wmw-65x9/GHSA-v2rg-3wmw-65x9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wv5q-x2gm-xf7j/GHSA-wv5q-x2gm-xf7j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wwrf-457v-6cqw/GHSA-wwrf-457v-6cqw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x226-jp3j-r3hc/GHSA-x226-jp3j-r3hc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xh3w-9cjp-3cf8/GHSA-xh3w-9cjp-3cf8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xrxq-x8xp-9x7h/GHSA-xrxq-x8xp-9x7h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xvx6-286h-35qm/GHSA-xvx6-286h-35qm.json diff --git a/advisories/unreviewed/2023/06/GHSA-rgj6-mpw9-qm58/GHSA-rgj6-mpw9-qm58.json b/advisories/unreviewed/2023/06/GHSA-rgj6-mpw9-qm58/GHSA-rgj6-mpw9-qm58.json index 7a1e8a85442..ede1115ba69 100644 --- a/advisories/unreviewed/2023/06/GHSA-rgj6-mpw9-qm58/GHSA-rgj6-mpw9-qm58.json +++ b/advisories/unreviewed/2023/06/GHSA-rgj6-mpw9-qm58/GHSA-rgj6-mpw9-qm58.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rgj6-mpw9-qm58", - "modified": "2025-01-10T21:31:21Z", + "modified": "2025-05-13T03:31:12Z", "published": "2023-06-01T12:30:14Z", "aliases": [ "CVE-2023-22652" ], - "details": "A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files.\nThis issue affects libeconf: before 0.5.2.\n\n", + "details": "A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files.\nThis issue affects libeconf: before 0.5.2.", "severity": [ { "type": "CVSS_V3", @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://https://github.com/openSUSE/libeconf/issues/177" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00016.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SDD5GL5T3V5XZ3VFA4HPE6YGJ2K4HHPC" diff --git a/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json b/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json index 5a51851a764..a7d885de9a4 100644 --- a/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json +++ b/advisories/unreviewed/2024/04/GHSA-363m-3jp4-qg24/GHSA-363m-3jp4-qg24.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-h9pr-qr4v-f87f/GHSA-h9pr-qr4v-f87f.json b/advisories/unreviewed/2024/04/GHSA-h9pr-qr4v-f87f/GHSA-h9pr-qr4v-f87f.json index e934834628f..a2734687194 100644 --- a/advisories/unreviewed/2024/04/GHSA-h9pr-qr4v-f87f/GHSA-h9pr-qr4v-f87f.json +++ b/advisories/unreviewed/2024/04/GHSA-h9pr-qr4v-f87f/GHSA-h9pr-qr4v-f87f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mqx4-g9cq-jvc6/GHSA-mqx4-g9cq-jvc6.json b/advisories/unreviewed/2024/04/GHSA-mqx4-g9cq-jvc6/GHSA-mqx4-g9cq-jvc6.json index 0f0e7d9eb8d..029d0ad47fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-mqx4-g9cq-jvc6/GHSA-mqx4-g9cq-jvc6.json +++ b/advisories/unreviewed/2024/04/GHSA-mqx4-g9cq-jvc6/GHSA-mqx4-g9cq-jvc6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pgf5-9895-3ph9/GHSA-pgf5-9895-3ph9.json b/advisories/unreviewed/2024/04/GHSA-pgf5-9895-3ph9/GHSA-pgf5-9895-3ph9.json index 2d0b6d2235b..834cc681e84 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgf5-9895-3ph9/GHSA-pgf5-9895-3ph9.json +++ b/advisories/unreviewed/2024/04/GHSA-pgf5-9895-3ph9/GHSA-pgf5-9895-3ph9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-pgf5-9895-3ph9", - "modified": "2024-04-04T03:31:08Z", + "modified": "2025-05-13T03:31:12Z", "published": "2024-04-04T03:31:08Z", "aliases": [ "CVE-2024-2692" ], - "details": "SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.\n", + "details": "SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json b/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json index 811666bae04..6aa4fc6cf7d 100644 --- a/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json +++ b/advisories/unreviewed/2024/04/GHSA-w5wq-cvfc-3r8g/GHSA-w5wq-cvfc-3r8g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json b/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json index 3ba1bba4761..44c02d4d58c 100644 --- a/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json +++ b/advisories/unreviewed/2024/04/GHSA-wv8p-qvw7-q865/GHSA-wv8p-qvw7-q865.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-3xp5-7h92-mqvv/GHSA-3xp5-7h92-mqvv.json b/advisories/unreviewed/2024/06/GHSA-3xp5-7h92-mqvv/GHSA-3xp5-7h92-mqvv.json index 9197dfa506d..25ef807e7f3 100644 --- a/advisories/unreviewed/2024/06/GHSA-3xp5-7h92-mqvv/GHSA-3xp5-7h92-mqvv.json +++ b/advisories/unreviewed/2024/06/GHSA-3xp5-7h92-mqvv/GHSA-3xp5-7h92-mqvv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-97gr-9g44-39q4/GHSA-97gr-9g44-39q4.json b/advisories/unreviewed/2024/06/GHSA-97gr-9g44-39q4/GHSA-97gr-9g44-39q4.json index 45c0e2b9219..5cc829c3a9b 100644 --- a/advisories/unreviewed/2024/06/GHSA-97gr-9g44-39q4/GHSA-97gr-9g44-39q4.json +++ b/advisories/unreviewed/2024/06/GHSA-97gr-9g44-39q4/GHSA-97gr-9g44-39q4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-9fcr-j456-qxxg/GHSA-9fcr-j456-qxxg.json b/advisories/unreviewed/2024/06/GHSA-9fcr-j456-qxxg/GHSA-9fcr-j456-qxxg.json index a25ce895a88..a0fb42429a1 100644 --- a/advisories/unreviewed/2024/06/GHSA-9fcr-j456-qxxg/GHSA-9fcr-j456-qxxg.json +++ b/advisories/unreviewed/2024/06/GHSA-9fcr-j456-qxxg/GHSA-9fcr-j456-qxxg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json b/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json index 53efc46bc33..45ae02f0b5f 100644 --- a/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json +++ b/advisories/unreviewed/2024/06/GHSA-mgqc-jwxc-fx8x/GHSA-mgqc-jwxc-fx8x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json b/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json index af61f5ba667..3a2835a433a 100644 --- a/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json +++ b/advisories/unreviewed/2024/06/GHSA-qp28-67v3-65qc/GHSA-qp28-67v3-65qc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json b/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json index 8ec6b7caf90..80088490b78 100644 --- a/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json +++ b/advisories/unreviewed/2024/06/GHSA-rgw4-v387-9jvw/GHSA-rgw4-v387-9jvw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json b/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json index a5203ddf591..33fec977de0 100644 --- a/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json +++ b/advisories/unreviewed/2024/06/GHSA-w8j6-vhx2-7qvh/GHSA-w8j6-vhx2-7qvh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-9cxr-86mw-8jw2/GHSA-9cxr-86mw-8jw2.json b/advisories/unreviewed/2024/09/GHSA-9cxr-86mw-8jw2/GHSA-9cxr-86mw-8jw2.json index e9a62de93ff..f0ed49e1f7e 100644 --- a/advisories/unreviewed/2024/09/GHSA-9cxr-86mw-8jw2/GHSA-9cxr-86mw-8jw2.json +++ b/advisories/unreviewed/2024/09/GHSA-9cxr-86mw-8jw2/GHSA-9cxr-86mw-8jw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9cxr-86mw-8jw2", - "modified": "2024-09-26T03:30:40Z", + "modified": "2025-05-13T03:31:13Z", "published": "2024-09-26T03:30:40Z", "aliases": [ "CVE-2024-8404" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.papercut.com/kb/Main/Security-Bulletin-May-2024" + }, + { + "type": "WEB", + "url": "https://www.papercut.com/kb/Main/Security-Bulletin-May-2025" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-3xfw-592p-fx76/GHSA-3xfw-592p-fx76.json b/advisories/unreviewed/2025/05/GHSA-3xfw-592p-fx76/GHSA-3xfw-592p-fx76.json new file mode 100644 index 00000000000..5a001b1ddca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3xfw-592p-fx76/GHSA-3xfw-592p-fx76.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xfw-592p-fx76", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-30012" + ], + "details": "The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM stack to accept binary Java objects in specific encoding format. On successful exploitation, an authenticated attacker with high privileges could send malicious payload request and receive an outbound DNS request, resulting in deserialization of data in the application. This vulnerability has low impact on confidentiality, integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30012" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3578900" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5x6q-c4xg-h54m/GHSA-5x6q-c4xg-h54m.json b/advisories/unreviewed/2025/05/GHSA-5x6q-c4xg-h54m/GHSA-5x6q-c4xg-h54m.json new file mode 100644 index 00000000000..f9008c3a047 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5x6q-c4xg-h54m/GHSA-5x6q-c4xg-h54m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x6q-c4xg-h54m", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-31329" + ], + "details": "SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed by the victim, sensitive information such as user credentials is exposed. These credentials may then be used to gain unauthorized access to local or adjacent systems. This results in high impact to Confidentiality, with no significant effect on Integrity or Availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31329" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3577287" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-141" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-73c9-m6v4-gr66/GHSA-73c9-m6v4-gr66.json b/advisories/unreviewed/2025/05/GHSA-73c9-m6v4-gr66/GHSA-73c9-m6v4-gr66.json new file mode 100644 index 00000000000..bb083cffa3c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-73c9-m6v4-gr66/GHSA-73c9-m6v4-gr66.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73c9-m6v4-gr66", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43005" + ], + "details": "SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue does not impact the Integrity or Availability of the application, it may have a Low impact on the Confidentiality of data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43005" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3574520" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7r36-ppxr-258g/GHSA-7r36-ppxr-258g.json b/advisories/unreviewed/2025/05/GHSA-7r36-ppxr-258g/GHSA-7r36-ppxr-258g.json new file mode 100644 index 00000000000..ab62bb99246 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7r36-ppxr-258g/GHSA-7r36-ppxr-258g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r36-ppxr-258g", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43007" + ], + "details": "SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on confidentiality, integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43007" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/2719724" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-94gr-9qc8-c44p/GHSA-94gr-9qc8-c44p.json b/advisories/unreviewed/2025/05/GHSA-94gr-9qc8-c44p/GHSA-94gr-9qc8-c44p.json new file mode 100644 index 00000000000..87e57ef571d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-94gr-9qc8-c44p/GHSA-94gr-9qc8-c44p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94gr-9qc8-c44p", + "modified": "2025-05-13T03:31:15Z", + "published": "2025-05-13T03:31:15Z", + "aliases": [ + "CVE-2025-43010" + ], + "details": "SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a certain function module remotely and replace arbitrary ABAP programs, including SAP standard programs. This is due to lack of input validation and no authorization checks. This has low Confidentiality impact but high impact on integrity and availability to the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43010" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3600859" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c382-rxwx-qqcr/GHSA-c382-rxwx-qqcr.json b/advisories/unreviewed/2025/05/GHSA-c382-rxwx-qqcr/GHSA-c382-rxwx-qqcr.json new file mode 100644 index 00000000000..92585ab5a62 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c382-rxwx-qqcr/GHSA-c382-rxwx-qqcr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c382-rxwx-qqcr", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-30010" + ], + "details": "The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30010" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3578900" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c588-wghg-39q4/GHSA-c588-wghg-39q4.json b/advisories/unreviewed/2025/05/GHSA-c588-wghg-39q4/GHSA-c588-wghg-39q4.json new file mode 100644 index 00000000000..6ac5accc797 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c588-wghg-39q4/GHSA-c588-wghg-39q4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c588-wghg-39q4", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43003" + ], + "details": "SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive information. This could cause a high impact on confidentiality and minimal impact on integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43003" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3596033" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c9j5-3rxr-ch9p/GHSA-c9j5-3rxr-ch9p.json b/advisories/unreviewed/2025/05/GHSA-c9j5-3rxr-ch9p/GHSA-c9j5-3rxr-ch9p.json new file mode 100644 index 00000000000..a798ada2cef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c9j5-3rxr-ch9p/GHSA-c9j5-3rxr-ch9p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9j5-3rxr-ch9p", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-42997" + ], + "details": "Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality, integrity, and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-42997" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3577300" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cww2-f4cr-g22m/GHSA-cww2-f4cr-g22m.json b/advisories/unreviewed/2025/05/GHSA-cww2-f4cr-g22m/GHSA-cww2-f4cr-g22m.json new file mode 100644 index 00000000000..6e63bac3c62 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cww2-f4cr-g22m/GHSA-cww2-f4cr-g22m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cww2-f4cr-g22m", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43006" + ], + "details": "SAP Supplier Relationship Management (Master Data Management Catalogue) allows an unauthenticated attacker to execute malicious scripts in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43006" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3588455" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json index 130d52a4dbf..f6c7638c996 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json +++ b/advisories/unreviewed/2025/05/GHSA-f2w6-r722-5fr8/GHSA-f2w6-r722-5fr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2w6-r722-5fr8", - "modified": "2025-05-13T00:31:10Z", + "modified": "2025-05-13T03:31:13Z", "published": "2025-05-07T18:30:50Z", "aliases": [ "CVE-2025-47203" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/12/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/13/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-fffx-47hq-rh2f/GHSA-fffx-47hq-rh2f.json b/advisories/unreviewed/2025/05/GHSA-fffx-47hq-rh2f/GHSA-fffx-47hq-rh2f.json new file mode 100644 index 00000000000..b9041e56708 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fffx-47hq-rh2f/GHSA-fffx-47hq-rh2f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fffx-47hq-rh2f", + "modified": "2025-05-13T03:31:15Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43009" + ], + "details": "SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43009" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/2491817" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxhc-gwf9-69jh/GHSA-fxhc-gwf9-69jh.json b/advisories/unreviewed/2025/05/GHSA-fxhc-gwf9-69jh/GHSA-fxhc-gwf9-69jh.json new file mode 100644 index 00000000000..203e5f3205c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fxhc-gwf9-69jh/GHSA-fxhc-gwf9-69jh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxhc-gwf9-69jh", + "modified": "2025-05-13T03:31:15Z", + "published": "2025-05-13T03:31:15Z", + "aliases": [ + "CVE-2025-43011" + ], + "details": "Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43011" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3591978" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j2cw-3q46-v5jg/GHSA-j2cw-3q46-v5jg.json b/advisories/unreviewed/2025/05/GHSA-j2cw-3q46-v5jg/GHSA-j2cw-3q46-v5jg.json new file mode 100644 index 00000000000..2b8ed0abf8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j2cw-3q46-v5jg/GHSA-j2cw-3q46-v5jg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2cw-3q46-v5jg", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-30009" + ], + "details": "he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30009" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3578900" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q59c-g8h6-83g2/GHSA-q59c-g8h6-83g2.json b/advisories/unreviewed/2025/05/GHSA-q59c-g8h6-83g2/GHSA-q59c-g8h6-83g2.json new file mode 100644 index 00000000000..33636542cba --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q59c-g8h6-83g2/GHSA-q59c-g8h6-83g2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q59c-g8h6-83g2", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43004" + ], + "details": "Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access customer data when they access these dashboards. Since no mechanisms exist to enforce authentication, malicious unauthenticated users can view non-sensitive customer information. However, this does not affect data integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43004" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3571096" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json b/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json new file mode 100644 index 00000000000..0d036e2f641 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rgq9-rg7j-xm4x/GHSA-rgq9-rg7j-xm4x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgq9-rg7j-xm4x", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-42999" + ], + "details": "SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-42999" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3604119" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v2rg-3wmw-65x9/GHSA-v2rg-3wmw-65x9.json b/advisories/unreviewed/2025/05/GHSA-v2rg-3wmw-65x9/GHSA-v2rg-3wmw-65x9.json new file mode 100644 index 00000000000..ae1949d5da0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v2rg-3wmw-65x9/GHSA-v2rg-3wmw-65x9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2rg-3wmw-65x9", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43002" + ], + "details": "SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43002" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3227940" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-472" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wv5q-x2gm-xf7j/GHSA-wv5q-x2gm-xf7j.json b/advisories/unreviewed/2025/05/GHSA-wv5q-x2gm-xf7j/GHSA-wv5q-x2gm-xf7j.json new file mode 100644 index 00000000000..5df7acadc74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wv5q-x2gm-xf7j/GHSA-wv5q-x2gm-xf7j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv5q-x2gm-xf7j", + "modified": "2025-05-13T03:31:15Z", + "published": "2025-05-13T03:31:15Z", + "aliases": [ + "CVE-2025-35471" + ], + "details": "conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35471" + }, + { + "type": "WEB", + "url": "https://github.com/conda-forge/openssl-feedstock/issues/201" + }, + { + "type": "WEB", + "url": "https://github.com/conda-forge/openssl-feedstock/commit/066e83c5226bafe90a9c0575b077ce30cd5f5921" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wwrf-457v-6cqw/GHSA-wwrf-457v-6cqw.json b/advisories/unreviewed/2025/05/GHSA-wwrf-457v-6cqw/GHSA-wwrf-457v-6cqw.json new file mode 100644 index 00000000000..0d09d772be9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wwrf-457v-6cqw/GHSA-wwrf-457v-6cqw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwrf-457v-6cqw", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-30018" + ], + "details": "The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30018" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3578900" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x226-jp3j-r3hc/GHSA-x226-jp3j-r3hc.json b/advisories/unreviewed/2025/05/GHSA-x226-jp3j-r3hc/GHSA-x226-jp3j-r3hc.json new file mode 100644 index 00000000000..fd90ca0b352 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x226-jp3j-r3hc/GHSA-x226-jp3j-r3hc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x226-jp3j-r3hc", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43000" + ], + "details": "Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43000" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3586013" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xh3w-9cjp-3cf8/GHSA-xh3w-9cjp-3cf8.json b/advisories/unreviewed/2025/05/GHSA-xh3w-9cjp-3cf8/GHSA-xh3w-9cjp-3cf8.json new file mode 100644 index 00000000000..9af7b20d9b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xh3w-9cjp-3cf8/GHSA-xh3w-9cjp-3cf8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh3w-9cjp-3cf8", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-26662" + ], + "details": "The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26662" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3558755" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xrxq-x8xp-9x7h/GHSA-xrxq-x8xp-9x7h.json b/advisories/unreviewed/2025/05/GHSA-xrxq-x8xp-9x7h/GHSA-xrxq-x8xp-9x7h.json new file mode 100644 index 00000000000..e3cf2d77196 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xrxq-x8xp-9x7h/GHSA-xrxq-x8xp-9x7h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrxq-x8xp-9x7h", + "modified": "2025-05-13T03:31:13Z", + "published": "2025-05-13T03:31:13Z", + "aliases": [ + "CVE-2025-30011" + ], + "details": "The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the application, which could disclose the internal version details of the affected system. This vulnerability has low impact on confidentiality, with no effect on integrity and availability of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30011" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3578900" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xvx6-286h-35qm/GHSA-xvx6-286h-35qm.json b/advisories/unreviewed/2025/05/GHSA-xvx6-286h-35qm/GHSA-xvx6-286h-35qm.json new file mode 100644 index 00000000000..e7ed2e5a600 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xvx6-286h-35qm/GHSA-xvx6-286h-35qm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvx6-286h-35qm", + "modified": "2025-05-13T03:31:14Z", + "published": "2025-05-13T03:31:14Z", + "aliases": [ + "CVE-2025-43008" + ], + "details": "Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43008" + }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/3585992" + }, + { + "type": "WEB", + "url": "https://url.sap/sapsecuritypatchday" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T01:15:49Z" + } +} \ No newline at end of file