Lucene search

K
cvelistJpcertCVELIST:CVE-2023-38751
HistoryAug 09, 2023 - 3:29 a.m.

CVE-2023-38751

2023-08-0903:29:37
jpcert
www.cve.org
improper authorization
special interest group network for analysis and liaison
api users
non-disclosure

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization information of the information receiver that is set as β€œnon-disclosure” in the information provision operation.

CNA Affected

[
  {
    "vendor": " Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)",
    "product": "Special Interest Group Network for Analysis and Liaison",
    "versions": [
      {
        "version": "versions 4.4.0 to 4.7.7",
        "status": "affected"
      }
    ]
  }
]

4.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for CVELIST:CVE-2023-38751