CVE-2020-4367
published 2020-06-02CVE-2020-4367: IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.79%
52.1th percentile
IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179001.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| ibm | planning_analytics_local | — | — |
| ibm | planning_analytics_local | >= 2.0.0 < 2.0.9.1 | 2.0.9.1 |
| linux | linux_kernel | >= 0 < 5.4.0-33.37 | 5.4.0-33.37 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjgp-x6xf-xjc9: IBM Planning Analytics Local 2
ghsa_unreviewed·2022-05-24
CVE-2020-4367 [MEDIUM] GHSA-cjgp-x6xf-xjc9: IBM Planning Analytics Local 2
IBM Planning Analytics Local 2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179001.
OSV
linux regression
osv·2020-05-28·CVSS 7.8
linux regression
linux regression
USN-4367-1 fixed vulnerabilities in the 5.4 Linux kernel. Unfortunately,
that update introduced a regression in overlayfs. This update corrects
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the btrfs implementation in the Linux kernel did not
properly detect that a block was marked dirty in some situations. An
attacker could use this to specially craft a file system image that, when
unmounted, could cause a denial of service (system crash). (CVE-2019-19377)
It was discovered that the linux kernel did not properly validate certain
mount options to the tmpfs virtual memory file system. A local attacker
with the ability to specify mount options could use this to cause a denial
of service (system crash). (CVE-2020-11565
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4367
vendor_chrome·2023-08-25·CVSS 3.6
CVE-2023-4367 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-4367
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-4367: Insufficient policy enforcement in Extensions API. Reported by Axel Chong on 2023-07-26 [$500][ 1467751 ] Medium CVE-2023-4368: Insufficient policy enforcement in Extensions API
Reported by Axel Chong on 2023-07-26 Android Runtime Container Security Fixes: [NA] [NA] High Fixes CVE-2023-21264 on impacted platforms [NA] [NA] High Fixes CVE-2020-29374 on impacted platforms We would like to thank the security researchers that report vulnerabilities to us via bughunters
Severity: medium
Suricata
ET WEB_SPECIFIC_APPS Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Attempt
suricata·2011-03-01
CVE-2010-4367 ET WEB_SPECIFIC_APPS Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Attempt
ET WEB_SPECIFIC_APPS Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Awstats Apache Tomcat Configuration File Remote Arbitrary Command Execution Attempt"; flow:established,to_server; http.uri; content:"awstats.cgi"; nocase; content:"config="; nocase; content:"pluginmode=rawlog"; nocase; content:"configdir=|5C 5C|"; nocase; fast_pattern; reference:bid,45123; reference:cve,2010-4367; classtype:web-application-attack; sid:2012393; rev:4; metadata:created_at 2011_03_01, cve CVE_2010_4367, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_13;)
No public exploits indexed.
No writeups or analysis indexed.
2020-06-02
Published