CVE-2017-1336
published 2017-12-07CVE-2017-1336: IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.
PriorityP419medium4.4CVSS 3.0
AVNACHPRLUIRSCCLILAN
EPSS
0.68%
48.0th percentile
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | biginsights | — | — |
| ibm | infosphere_biginsights | — | — |
| shopware | core | >= 0 < 6.4.20.1 | 6.4.20.1 |
| shopware | platform | >= 0 < 6.4.20.1 | 6.4.20.1 |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.6LOWAV:N/AC:H/Au:S/C:P/I:P/A:N
ghsa8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Shopware Has Improper Control of Generation of Code in Twig rendered views
ghsa·2023-04-18·CVSS 8.8
CVE-2023-2017 [CRITICAL] CWE-1336 Shopware Has Improper Control of Generation of Code in Twig rendered views
Shopware Has Improper Control of Generation of Code in Twig rendered views
### Impact
We fixed with [CVE-2023-22731](https://github.com/shopware/platform/security/advisories/GHSA-93cw-f5jj-x85w) Twig filters to only be executed with allowed functions. It is possible to pass PHP Closures as string or an array and array crafted PHP Closures was not checked against allow list
### Patches
The problem has been fixed with 6.4.20.1 with an improved override.
### Workarounds
For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
GHSA
GHSA-x858-rx52-6qvm: IBM Infosphere BigInsights 4
ghsa_unreviewed·2022-05-14
CVE-2017-1336 [MEDIUM] CWE-94 GHSA-x858-rx52-6qvm: IBM Infosphere BigInsights 4
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.ibm.com/support/docview.wss?uid=swg22010812http://www.securityfocus.com/bid/102061https://exchange.xforce.ibmcloud.com/vulnerabilities/126244http://www.ibm.com/support/docview.wss?uid=swg22010812http://www.securityfocus.com/bid/102061https://exchange.xforce.ibmcloud.com/vulnerabilities/126244
2017-12-07
Published