Show plain JSON{"id": "CVE-2017-8974", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": true, "impactScore": 4.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 4.4, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 2.5, "exploitabilityScore": 1.8}]}, "published": "2018-02-15T22:29:09.077", "references": [{"url": "http://www.securityfocus.com/bid/102530", "tags": ["Third Party Advisory", "VDB Entry"], "source": "security-alert@hpe.com"}, {"url": "https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbns03804en_us", "tags": ["Vendor Advisory"], "source": "security-alert@hpe.com"}, {"url": "http://www.securityfocus.com/bid/102530", "tags": ["Third Party Advisory", "VDB Entry"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbns03804en_us", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found."}, {"lang": "es", "value": "En la versi\u00f3n 1.0 de SAP HANA Extended Application Services, una contrase\u00f1a keystore plana se escribe en un archivo de registro del sistema, lo que podr\u00eda poner en peligro la confidencialidad de la comunicaci\u00f3n SSL."}], "lastModified": "2024-11-21T03:35:06.307", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:hp:nonstop_server_software:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB8E3429-4707-4147-B517-2FA1761611DF", "versionEndIncluding": "t6533h04\\^adf", "versionStartIncluding": "t6533h02"}, {"criteria": "cpe:2.3:a:hp:nonstop_server_software:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31E59888-AEC4-442C-BE32-48B71954AA93", "versionEndIncluding": "t6533l01\\^adn", "versionStartIncluding": "t6533l01"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:hp:nonstop_server:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "17C2C32B-5ABC-4679-9A99-F17829E36182"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "security-alert@hpe.com"}