Lucene search

K
nvd[email protected]NVD:CVE-2019-17495
HistoryOct 10, 2019 - 10:15 p.m.

CVE-2019-17495

2019-10-1022:15:10
CWE-352
web.nvd.nist.gov
9

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.017

Percentile

88.0%

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

Affected configurations

Nvd
Node
smartbearswagger_uiRange<3.23.11
Node
oraclebanking_apisRange18.118.3
OR
oraclebanking_apisMatch19.1
OR
oraclebanking_apisMatch19.2
OR
oraclebanking_apisMatch20.1
OR
oraclebanking_apisMatch21.1
OR
oraclebanking_digital_experienceRange18.118.3
OR
oraclebanking_digital_experienceMatch19.1
OR
oraclebanking_digital_experienceMatch19.2
OR
oraclebanking_digital_experienceMatch20.1
OR
oraclebanking_digital_experienceMatch21.1
OR
oraclebanking_platformRange2.4.02.10.0
OR
oracleprimavera_gatewayRange16.2.016.2.11
OR
oracleprimavera_gatewayRange17.12.017.12.8
OR
oracleutilities_frameworkMatch4.3.0.6.0
OR
oracleutilities_frameworkMatch4.4.0.0.0
OR
oracleutilities_frameworkMatch4.4.0.2.0
VendorProductVersionCPE
smartbearswagger_ui*cpe:2.3:a:smartbear:swagger_ui:*:*:*:*:*:*:*:*
oraclebanking_apis*cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*
oraclebanking_apis19.1cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
oraclebanking_apis19.2cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
oraclebanking_apis20.1cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
oraclebanking_apis21.1cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
oraclebanking_digital_experience*cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:*
oraclebanking_digital_experience19.1cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
oraclebanking_digital_experience19.2cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
oraclebanking_digital_experience20.1cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.017

Percentile

88.0%