{
  "CVE_data_type" : "CVE",
  "CVE_data_format" : "MITRE",
  "CVE_data_version" : "4.0",
  "CVE_data_numberOfCVEs" : "10334",
  "CVE_data_timestamp" : "2020-09-15T08:29Z",
  "CVE_Items" : [ {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0001",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0002",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "jscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vbscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034648",
          "name" : "1034648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034650",
          "name" : "1034650",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-001",
          "name" : "MS16-001",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-003",
          "name" : "MS16-003",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1215",
          "name" : "20160112 Microsoft Internet Explorer VBScript \"Assignvar\" Use-After-Free Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:jscript:5.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:jscript:5.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:vbscript:5.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:vbscript:5.8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0003",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034649",
          "name" : "1034649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-019",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-019",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-002",
          "name" : "MS16-002",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka \"Microsoft Edge Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.6,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 6.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0004",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0005",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034648",
          "name" : "1034648",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-001",
          "name" : "MS16-001",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka \"Internet Explorer Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0006",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79882",
          "name" : "79882",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034645",
          "name" : "1034645",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-008",
          "name" : "MS16-008",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39311/",
          "name" : "39311",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka \"Windows Mount Point Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0007."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.3,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.3,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-17T20:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0007",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79898",
          "name" : "79898",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034645",
          "name" : "1034645",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://code.google.com/p/google-security-research/issues/detail?id=589",
          "name" : "https://code.google.com/p/google-security-research/issues/detail?id=589",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-008",
          "name" : "MS16-008",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39310/",
          "name" : "39310",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39311/",
          "name" : "39311",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka \"Windows Mount Point Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0006."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-17T20:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0008",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034654",
          "name" : "1034654",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-005",
          "name" : "MS16-005",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1216",
          "name" : "20160112 Microsoft Wordpad Open Document Text OOBR Heap Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Not Applicable" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka \"Windows GDI32.dll ASLR Bypass Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-15T19:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0009",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034654",
          "name" : "1034654",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-005",
          "name" : "MS16-005",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka \"Win32k Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0010",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "powerpoint_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034651",
          "name" : "1034651",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-004",
          "name" : "MS16-004",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, Excel 2016 for Mac, PowerPoint 2016 for Mac, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0011",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "sharepoint_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034653",
          "name" : "1034653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-004",
          "name" : "MS16-004",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka \"Microsoft SharePoint Security Feature Bypass,\" a different vulnerability than CVE-2015-6117."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0012",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "powerpoint",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visio",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "visual_basics",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034651",
          "name" : "1034651",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-004",
          "name" : "MS16-004",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka \"Microsoft Office ASLR Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:powerpoint:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visio:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:visual_basics:6.0:*:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0013",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0014",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-426"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034661",
          "name" : "1034661",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007",
          "name" : "MS16-007",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka \"DLL Loading Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-16T18:24Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0015",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/135232/Microsoft-DirectShow-Remote-Code-Execution.html",
          "name" : "http://packetstormsecurity.com/files/135232/Microsoft-DirectShow-Remote-Code-Execution.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034660",
          "name" : "1034660",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007",
          "name" : "MS16-007",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39232/",
          "name" : "39232",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka \"DirectShow Heap Corruption Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-17T19:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0016",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-426"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034661",
          "name" : "1034661",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://code.google.com/p/google-security-research/issues/detail?id=555",
          "name" : "https://code.google.com/p/google-security-research/issues/detail?id=555",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007",
          "name" : "MS16-007",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39233/",
          "name" : "39233",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka \"DLL Loading Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-15T14:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0017",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0018",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-426"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034661",
          "name" : "1034661",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007",
          "name" : "MS16-007",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka \"DLL Loading Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.3,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.3,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2019-05-15T18:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0019",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034659",
          "name" : "1034659",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007",
          "name" : "MS16-007",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allows remote attackers to bypass intended access restrictions and establish sessions for blank-password accounts via a modified RDP client, aka \"Windows Remote Desktop Protocol Security Bypass Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:x86:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0020",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034661",
          "name" : "1034661",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-018",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-018",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-007",
          "name" : "MS16-007",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka \"MAPI DLL Loading Elevation of Privilege Vulnerability.\""
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/426.html\">CWE-426: Untrusted Search Path</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0021",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "infopath",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84024",
          "name" : "84024",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035207",
          "name" : "1035207",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-029",
          "name" : "MS16-029",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:infopath:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:infopath:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:infopath:2013:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0022",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034975",
          "name" : "1034975",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034976",
          "name" : "1034976",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0052."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0023",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0024",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79891",
          "name" : "79891",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034649",
          "name" : "1034649",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-002",
          "name" : "MS16-002",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka \"Scripting Engine Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0025",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_online_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036093",
          "name" : "1036093",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-070",
          "name" : "MS16-070",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_online_server:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.3,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.3,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-16T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0026",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1607",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2016",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93998",
          "name" : "93998",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037252",
          "name" : "1037252",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-134",
          "name" : "MS16-134",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka \"Windows Common Log File System Driver Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-3332, CVE-2016-3333, CVE-2016-3334, CVE-2016-3335, CVE-2016-3338, CVE-2016-3340, CVE-2016-3342, CVE-2016-3343, and CVE-2016-7184."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-11-10T06:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0027",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0028",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "outlook_web_access",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036106",
          "name" : "1036106",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-079",
          "name" : "MS16-079",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka \"Microsoft Exchange Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_11:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_12:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:outlook_web_access:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-16T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0029",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79889",
          "name" : "79889",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034647",
          "name" : "1034647",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-010",
          "name" : "MS16-010",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka \"Exchange Spoofing Vulnerability,\" a different vulnerability than CVE-2016-0031."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2020-04-09T13:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0030",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79890",
          "name" : "79890",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034647",
          "name" : "1034647",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-010",
          "name" : "MS16-010",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka \"Exchange Spoofing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2020-04-09T13:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0031",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79888",
          "name" : "79888",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034647",
          "name" : "1034647",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-010",
          "name" : "MS16-010",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka \"Exchange Spoofing Vulnerability,\" a different vulnerability than CVE-2016-0029."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2020-04-09T13:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0032",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/79884",
          "name" : "79884",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034647",
          "name" : "1034647",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-010",
          "name" : "MS16-010",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka \"Exchange Spoofing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_11:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2020-04-09T13:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0033",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-94"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034983",
          "name" : "1034983",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-019",
          "name" : "MS16-019",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka \".NET Framework Stack Overflow Denial of Service Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0034",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "silverlight",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034655",
          "name" : "1034655",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-006",
          "name" : "MS16-006",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka \"Silverlight Runtime Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:silverlight:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0035",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034651",
          "name" : "1034651",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-15-639",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-15-639",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-004",
          "name" : "MS16-004",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-13T05:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0036",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034981",
          "name" : "1034981",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-017",
          "name" : "MS16-017",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote authenticated users to execute arbitrary code via crafted data, aka \"Remote Desktop Protocol (RDP) Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-15T18:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0037",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/82507",
          "name" : "82507",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034984",
          "name" : "1034984",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-020",
          "name" : "MS16-020",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka \"Microsoft Active Directory Federation Services Denial of Service Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:datacenter:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:essentials:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:standard:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-08T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0038",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034974",
          "name" : "1034974",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-013",
          "name" : "MS16-013",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1219",
          "name" : "20160209 Microsoft Windows Journal File Parsing \"TIFFControl\" Invalid Reference Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Not Applicable" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka \"Windows Journal Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-15T15:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0039",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "sharepoint_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034975",
          "name" : "1034975",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka \"Microsoft SharePoint XSS Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0040",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034985",
          "name" : "1034985",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-014",
          "name" : "MS16-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/44586/",
          "name" : "44586",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka \"Windows Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0041",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/fulldisclosure/2016/Feb/49",
          "name" : "20160210 NPS Datastore server DLL side loading vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034985",
          "name" : "1034985",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-014",
          "name" : "MS16-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.securify.nl/advisory/SFY20150905/nps_datastore_server_dll_side_loading_vulnerability.html",
          "name" : "https://www.securify.nl/advisory/SFY20150905/nps_datastore_server_dll_side_loading_vulnerability.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka \"DLL Loading Remote Code Execution Vulnerability.\""
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/426.html\">CWE-426: Untrusted Search Path</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0042",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034985",
          "name" : "1034985",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-014",
          "name" : "MS16-014",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka \"Windows DLL Loading Remote Code Execution Vulnerability.\""
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/426.html\">CWE-426: Untrusted Search Path</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0043",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0044",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034985",
          "name" : "1034985",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-014",
          "name" : "MS16-014",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted \"change batch\" data, aka \"Windows DLL Loading Denial of Service Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-15T17:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0045",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0046",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034973",
          "name" : "1034973",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-156",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-156",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-012",
          "name" : "MS16-012",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Windows Reader in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote attackers to execute arbitrary code via a crafted Reader file, aka \"Microsoft Windows Reader Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-15T14:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0047",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034983",
          "name" : "1034983",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-019",
          "name" : "MS16-019",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka \"Windows Forms Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0048",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034982",
          "name" : "1034982",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-018",
          "name" : "MS16-018",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0049",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/135797/Windows-Kerberos-Security-Feature-Bypass.html",
          "name" : "http://packetstormsecurity.com/files/135797/Windows-Kerberos-Security-Feature-Bypass.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82535",
          "name" : "82535",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034985",
          "name" : "1034985",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-014",
          "name" : "MS16-014",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39442/",
          "name" : "39442",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka \"Windows Kerberos Security Feature Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.2,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0050",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034986",
          "name" : "1034986",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-021",
          "name" : "MS16-021",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka \"Network Policy Server RADIUS Implementation Denial of Service Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:gold:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:datacenter:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:essentials:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:standard:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-08T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0051",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034980",
          "name" : "1034980",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-016",
          "name" : "MS16-016",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39432/",
          "name" : "39432",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39788/",
          "name" : "39788",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40085/",
          "name" : "40085",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"WebDAV Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0052",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034975",
          "name" : "1034975",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034976",
          "name" : "1034976",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0022."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0053",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034975",
          "name" : "1034975",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034976",
          "name" : "1034976",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps Server 2013 SP1, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0054",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_designer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034976",
          "name" : "1034976",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x64:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:x86:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_designer:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0055",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034976",
          "name" : "1034976",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0056",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034976",
          "name" : "1034976",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-015",
          "name" : "MS16-015",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0057",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84030",
          "name" : "84030",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035207",
          "name" : "1035207",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-029",
          "name" : "MS16-029",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka \"Microsoft Office Security Feature Bypass Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0058",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034973",
          "name" : "1034973",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-012",
          "name" : "MS16-012",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the PDF Library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote attackers to execute arbitrary code via a crafted PDF document that triggers API calls, aka \"Microsoft PDF Library Buffer Overflow Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2019-05-15T18:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0059",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka \"Internet Explorer Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0060",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034972",
          "name" : "1034972",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-159",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-159",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-165",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-165",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-011",
          "name" : "MS16-011",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0061, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0061",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034972",
          "name" : "1034972",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-162",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-162",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-011",
          "name" : "MS16-011",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0062",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034972",
          "name" : "1034972",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-158",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-158",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-011",
          "name" : "MS16-011",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0063",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.skylined.nl/20161128001.html",
          "name" : "http://blog.skylined.nl/20161128001.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-166",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-166",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40845/",
          "name" : "40845",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0067, and CVE-2016-0072."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0064",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0065",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0066",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0067",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0063, and CVE-2016-0072."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0068",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka \"Internet Explorer Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0069."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-18T22:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0069",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://jvn.jp/en/jp/JVN78383854/index.html",
          "name" : "JVN#78383854",
          "refsource" : "JVN",
          "tags" : [ ]
        }, {
          "url" : "http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000028.html",
          "name" : "JVNDB-2016-000028",
          "refsource" : "JVNDB",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82665",
          "name" : "82665",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka \"Internet Explorer Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0068."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-18T22:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0070",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1607",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93354",
          "name" : "93354",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-124",
          "name" : "MS16-124",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka \"Windows Kernel Local Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-10-14T02:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0071",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0072",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-157",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-157",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0063, and CVE-2016-0067."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0073",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1607",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93355",
          "name" : "93355",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-124",
          "name" : "MS16-124",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40574/",
          "name" : "40574",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka \"Windows Kernel Local Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0075."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.3,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-14T02:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0074",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0075",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1607",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93356",
          "name" : "93356",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-124",
          "name" : "MS16-124",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40573/",
          "name" : "40573",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka \"Windows Kernel Local Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0073."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-14T02:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0076",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0077",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-19"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034971",
          "name" : "1034971",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034972",
          "name" : "1034972",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-009",
          "name" : "MS16-009",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-011",
          "name" : "MS16-011",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge misparse HTTP responses, which allows remote attackers to spoof web sites via a crafted URL, aka \"Microsoft Browser Spoofing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0078",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0079",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1607",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93357",
          "name" : "93357",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-124",
          "name" : "MS16-124",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40608/",
          "name" : "40608",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka \"Windows Kernel Local Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.3,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-14T02:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0080",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/82631",
          "name" : "82631",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034972",
          "name" : "1034972",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-011",
          "name" : "MS16-011",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka \"Microsoft Edge ASLR Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0081",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0082",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0083",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0084",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/82635",
          "name" : "82635",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034972",
          "name" : "1034972",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-011",
          "name" : "MS16-011",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-10T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0085",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0086",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0087",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84032",
          "name" : "84032",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035209",
          "name" : "1035209",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-031",
          "name" : "MS16-031",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly validate handles, which allows local users to gain privileges via a crafted application, aka \"Windows Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0088",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035538",
          "name" : "1035538",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-045",
          "name" : "MS16-045",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka \"Hyper-V Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.3,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 6.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0089",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035538",
          "name" : "1035538",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-045",
          "name" : "MS16-045",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka \"Hyper-V Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 4.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0090",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035538",
          "name" : "1035538",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-045",
          "name" : "MS16-045",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka \"Hyper-V Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 4.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0091",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/83944",
          "name" : "83944",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035208",
          "name" : "1035208",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-182",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-182",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-030",
          "name" : "MS16-030",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka \"Windows OLE Memory Remote Code Execution Vulnerability,\" a different vulnerability than CVE-2016-0092."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0092",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84125",
          "name" : "84125",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035208",
          "name" : "1035208",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-181",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-181",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-030",
          "name" : "MS16-030",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka \"Windows OLE Memory Remote Code Execution Vulnerability,\" a different vulnerability than CVE-2016-0091."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0093",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84054",
          "name" : "84054",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035212",
          "name" : "1035212",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-034",
          "name" : "MS16-034",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39648/",
          "name" : "39648",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0094, CVE-2016-0095, and CVE-2016-0096."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0094",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84066",
          "name" : "84066",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035212",
          "name" : "1035212",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-034",
          "name" : "MS16-034",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39647/",
          "name" : "39647",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0093, CVE-2016-0095, and CVE-2016-0096."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0095",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84072",
          "name" : "84072",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035212",
          "name" : "1035212",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-196",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-196",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-034",
          "name" : "MS16-034",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0096",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84069",
          "name" : "84069",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035212",
          "name" : "1035212",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-034",
          "name" : "MS16-034",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0095."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0097",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0098",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84089",
          "name" : "84089",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035200",
          "name" : "1035200",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-027",
          "name" : "MS16-027",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 allow remote attackers to execute arbitrary code via crafted media content, aka \"Windows Media Parsing Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0099",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84034",
          "name" : "84034",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035210",
          "name" : "1035210",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-032",
          "name" : "MS16-032",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39574/",
          "name" : "39574",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39719/",
          "name" : "39719",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39809/",
          "name" : "39809",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40107/",
          "name" : "40107",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka \"Secondary Logon Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0100",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          }, {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/83930",
          "name" : "83930",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035205",
          "name" : "1035205",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-025",
          "name" : "MS16-025",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka \"Library Loading Input Validation Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0101",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84111",
          "name" : "84111",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035200",
          "name" : "1035200",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-027",
          "name" : "MS16-027",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via crafted media content, aka \"Windows Media Parsing Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0102",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84018",
          "name" : "84018",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0103",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84013",
          "name" : "84013",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0102, CVE-2016-0106, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0104",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84009",
          "name" : "84009",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0105",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84019",
          "name" : "84019",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0106",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84014",
          "name" : "84014",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-179",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-179",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-180",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-180",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0107",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84015",
          "name" : "84015",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-183",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-183",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0105, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0108",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84016",
          "name" : "84016",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39562/",
          "name" : "39562",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0109, and CVE-2016-0114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0109",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84020",
          "name" : "84020",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-184",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-184",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, and CVE-2016-0114."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0110",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84021",
          "name" : "84021",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 10 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0111",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84022",
          "name" : "84022",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39663/",
          "name" : "39663",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0112, and CVE-2016-0113."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0112",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84010",
          "name" : "84010",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-185",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-185",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-188",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-188",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0113."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0113",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84011",
          "name" : "84011",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-186",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-186",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0105, CVE-2016-0107, CVE-2016-0111, and CVE-2016-0112."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0114",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84012",
          "name" : "84012",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035203",
          "name" : "1035203",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-187",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-187",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-023",
          "name" : "MS16-023",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, and CVE-2016-0109."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0115",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0116",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0123, CVE-2016-0124, CVE-2016-0129, and CVE-2016-0130."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0117",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84109",
          "name" : "84109",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035202",
          "name" : "1035202",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-028",
          "name" : "MS16-028",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka \"Windows Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0118",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84112",
          "name" : "84112",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035202",
          "name" : "1035202",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-177",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-177",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-028",
          "name" : "MS16-028",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The PDF library in Microsoft Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka \"Windows Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0119",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0120",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84071",
          "name" : "84071",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035198",
          "name" : "1035198",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-026",
          "name" : "MS16-026",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39561/",
          "name" : "39561",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via a crafted OpenType font, aka \"OpenType Font Parsing Vulnerability.\""
        }, {
          "lang" : "en",
          "value" : "Per Microsoft:  \"For systems running Windows 10, an attacker who successfully exploited the vulnerability could potentially cause the application to stop responding instead of the system.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0121",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84027",
          "name" : "84027",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035198",
          "name" : "1035198",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-026",
          "name" : "MS16-026",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39560/",
          "name" : "39560",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka \"OpenType Font Parsing Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0122",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035525",
          "name" : "1035525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-042",
          "name" : "MS16-042",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39694/",
          "name" : "39694",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0123",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84114",
          "name" : "84114",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-178",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-178",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0116, CVE-2016-0124, CVE-2016-0129, and CVE-2016-0130."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0124",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84115",
          "name" : "84115",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0116, CVE-2016-0123, CVE-2016-0129, and CVE-2016-0130."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0125",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka \"Microsoft Edge Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.1,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0126",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89938",
          "name" : "89938",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035819",
          "name" : "1035819",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-054",
          "name" : "MS16-054",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0127",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035524",
          "name" : "1035524",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035525",
          "name" : "1035525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-042",
          "name" : "MS16-042",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0128",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://badlock.org/",
          "name" : "http://badlock.org/",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035534",
          "name" : "1035534",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa122",
          "name" : "https://bto.bluecoat.com/security-advisory/sa122",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-047",
          "name" : "MS16-047",
          "refsource" : "MS",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.kb.cert.org/vuls/id/813296",
          "name" : "VU#813296",
          "refsource" : "CERT-VN",
          "tags" : [ "Third Party Advisory", "US Government Resource" ]
        }, {
          "url" : "https://www.samba.org/samba/security/CVE-2016-2118.html",
          "name" : "https://www.samba.org/samba/security/CVE-2016-2118.html",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka \"Windows SAM and LSAD Downgrade Vulnerability\" or \"BADLOCK.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2019-09-27T17:21Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0129",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84116",
          "name" : "84116",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0116, CVE-2016-0123, CVE-2016-0124, and CVE-2016-0130."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0130",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84117",
          "name" : "84117",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035204",
          "name" : "1035204",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-024",
          "name" : "MS16-024",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0116, CVE-2016-0123, CVE-2016-0124, and CVE-2016-0129."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0131",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0132",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84075",
          "name" : "84075",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035213",
          "name" : "1035213",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-035",
          "name" : "MS16-035",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka \".NET XML Validation Security Feature Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0133",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84035",
          "name" : "84035",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035211",
          "name" : "1035211",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-033",
          "name" : "MS16-033",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The USB Mass Storage Class driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows physically proximate attackers to execute arbitrary code by inserting a crafted USB device, aka \"USB Mass Storage Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "PHYSICAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.8,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0134",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/84026",
          "name" : "84026",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035206",
          "name" : "1035206",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035207",
          "name" : "1035207",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-029",
          "name" : "MS16-029",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-09T11:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0135",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035541",
          "name" : "1035541",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-046",
          "name" : "MS16-046",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Secondary Logon Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0136",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_designer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035524",
          "name" : "1035524",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035525",
          "name" : "1035525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-042",
          "name" : "MS16-042",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1224",
          "name" : "20160412 Microsoft Excel Uninitialized Pointer Memory Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_designer:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_foundation:2010:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0137",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92785",
          "name" : "92785",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036785",
          "name" : "1036785",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-107",
          "name" : "MS16-107",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka \"Microsoft APP-V ASLR Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-09-14T10:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0138",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "exchange_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92806",
          "name" : "92806",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036778",
          "name" : "1036778",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-108",
          "name" : "MS16-108",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka \"Microsoft Exchange Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2010:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_12:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_13:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-14T10:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0139",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "excel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "excel_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035525",
          "name" : "1035525",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-042",
          "name" : "MS16-042",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Excel 2010 SP2, Word for Mac 2011, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:excel_viewer:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0140",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89953",
          "name" : "89953",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035819",
          "name" : "1035819",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-054",
          "name" : "MS16-054",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0141",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92903",
          "name" : "92903",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036785",
          "name" : "1036785",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-107",
          "name" : "MS16-107",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka \"Microsoft Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-09-14T10:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0142",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1607",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          }, {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93378",
          "name" : "93378",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036983",
          "name" : "1036983",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-122",
          "name" : "MS16-122",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web page, aka \"Microsoft Video Control Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-10-14T02:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0143",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/85896",
          "name" : "85896",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035529",
          "name" : "1035529",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035532",
          "name" : "1035532",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039",
          "name" : "MS16-039",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39712/",
          "name" : "39712",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0165 and CVE-2016-0167."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0144",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0145",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "live_meeting",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "lync",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "skype_for_business",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035528",
          "name" : "1035528",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035529",
          "name" : "1035529",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035530",
          "name" : "1035530",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035531",
          "name" : "1035531",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035532",
          "name" : "1035532",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039",
          "name" : "MS16-039",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39743/",
          "name" : "39743",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka \"Graphics Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:lync:2010:*:attendee:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0146",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0147",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "xml_core_services",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035523",
          "name" : "1035523",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-040",
          "name" : "MS16-040",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka \"MSXML 3.0 Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0148",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/136671/.NET-Framework-4.6-DLL-Hijacking.html",
          "name" : "http://packetstormsecurity.com/files/136671/.NET-Framework-4.6-DLL-Hijacking.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Apr/42",
          "name" : "20160412 .NET Framework 4.6 allows side loading of Windows API Set DLL",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/538063/100/0/threaded",
          "name" : "20160412 .NET Framework 4.6 allows side loading of Windows API Set DLL",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035535",
          "name" : "1035535",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-234",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-234",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-041",
          "name" : "MS16-041",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka \".NET Framework Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0149",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : ".net_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90026",
          "name" : "90026",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035842",
          "name" : "1035842",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-065",
          "name" : "MS16-065",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka \"TLS/SSL Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:.net_framework:4.6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0150",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-19"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035546",
          "name" : "1035546",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-049",
          "name" : "MS16-049",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka \"HTTP.sys Denial of Service Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0151",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035544",
          "name" : "1035544",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-048",
          "name" : "MS16-048",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39740/",
          "name" : "39740",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka \"Windows CSRSS Security Feature Bypass Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0152",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90020",
          "name" : "90020",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035834",
          "name" : "1035834",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-058",
          "name" : "MS16-058",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Internet Information Services (IIS) in Microsoft Windows Vista SP2 and Server 2008 SP2 mishandles library loading, which allows local users to gain privileges via a crafted application, aka \"Windows DLL Loading Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0153",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035536",
          "name" : "1035536",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-044",
          "name" : "MS16-044",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file, aka \"Windows OLE Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0154",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035521",
          "name" : "1035521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035522",
          "name" : "1035522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037",
          "name" : "MS16-037",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-038",
          "name" : "MS16-038",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0155",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035522",
          "name" : "1035522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-038",
          "name" : "MS16-038",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0156 and CVE-2016-0157."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0156",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035522",
          "name" : "1035522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-038",
          "name" : "MS16-038",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0155 and CVE-2016-0157."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0157",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035522",
          "name" : "1035522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-232",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-232",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-038",
          "name" : "MS16-038",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Edge Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0155 and CVE-2016-0156."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0158",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035522",
          "name" : "1035522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-233",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-233",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-038",
          "name" : "MS16-038",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka \"Microsoft Edge Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0161."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0159",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035521",
          "name" : "1035521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-231",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-231",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037",
          "name" : "MS16-037",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0160",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/136702/Microsoft-Internet-Explorer-11-DLL-Hijacking.html",
          "name" : "http://packetstormsecurity.com/files/136702/Microsoft-Internet-Explorer-11-DLL-Hijacking.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Apr/61",
          "name" : "20160416 Microsoft Internet Explorer 11 MSHTML.DLL Remote Binary Planting Vulnerability",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/538098/100/0/threaded",
          "name" : "20160415 Microsoft Internet Explorer 11 MSHTML.DLL Remote Binary Planting Vulnerability",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035521",
          "name" : "1035521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037",
          "name" : "MS16-037",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 mishandles DLL loading, which allows local users to gain privileges via a crafted application, aka \"DLL Loading Remote Code Execution Vulnerability.\""
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/426.html\">CWE-426: Untrusted Search Path</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0161",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035522",
          "name" : "1035522",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-038",
          "name" : "MS16-038",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka \"Microsoft Edge Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0158."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0162",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/85939",
          "name" : "85939",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035521",
          "name" : "1035521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037",
          "name" : "MS16-037",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka \"Internet Explorer Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0163",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0164",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/85922",
          "name" : "85922",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035521",
          "name" : "1035521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037",
          "name" : "MS16-037",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0165",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035529",
          "name" : "1035529",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035532",
          "name" : "1035532",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039",
          "name" : "MS16-039",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/44480/",
          "name" : "44480",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0167."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0166",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035521",
          "name" : "1035521",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-230",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-230",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-037",
          "name" : "MS16-037",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0167",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035529",
          "name" : "1035529",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035532",
          "name" : "1035532",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-039",
          "name" : "MS16-039",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0165."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T23:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0168",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137094/Microsoft-Windows-gdi32.dll-Information-Disclosure.html",
          "name" : "http://packetstormsecurity.com/files/137094/Microsoft-Windows-gdi32.dll-Information-Disclosure.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/89862",
          "name" : "89862",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035823",
          "name" : "1035823",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-055",
          "name" : "MS16-055",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka \"Windows Graphics Component Information Disclosure Vulnerability,\" a different vulnerability than CVE-2016-0169."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0169",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137095/Microsoft-Windows-gdi32.dll-Data-Copy.html",
          "name" : "http://packetstormsecurity.com/files/137095/Microsoft-Windows-gdi32.dll-Data-Copy.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/89863",
          "name" : "89863",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035823",
          "name" : "1035823",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-055",
          "name" : "MS16-055",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka \"Windows Graphics Component Information Disclosure Vulnerability,\" a different vulnerability than CVE-2016-0168."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0170",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137096/Microsoft-Windows-gdi32.dll-ExtEscape-Buffer-Overflow.html",
          "name" : "http://packetstormsecurity.com/files/137096/Microsoft-Windows-gdi32.dll-ExtEscape-Buffer-Overflow.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/89864",
          "name" : "89864",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035823",
          "name" : "1035823",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-055",
          "name" : "MS16-055",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka \"Windows Graphics Component RCE Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0171",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137502/Windows-7-win32k-Bitmap-Use-After-Free.html",
          "name" : "http://packetstormsecurity.com/files/137502/Windows-7-win32k-Bitmap-Use-After-Free.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/89860",
          "name" : "89860",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39959/",
          "name" : "39959",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0173, CVE-2016-0174, and CVE-2016-0196."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0172",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0173",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137503/Windows-7-win32k-Bitmap-Use-After-Free.html",
          "name" : "http://packetstormsecurity.com/files/137503/Windows-7-win32k-Bitmap-Use-After-Free.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/90064",
          "name" : "90064",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-279",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-279",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://bugs.chromium.org/p/project-zero/issues/detail?id=747",
          "name" : "https://bugs.chromium.org/p/project-zero/issues/detail?id=747",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39960/",
          "name" : "39960",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0171, CVE-2016-0174, and CVE-2016-0196."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0174",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90065",
          "name" : "90065",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-280",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-280",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0171, CVE-2016-0173, and CVE-2016-0196."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0175",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90027",
          "name" : "90027",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-281",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-281",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to obtain sensitive information about kernel-object addresses, and consequently bypass the KASLR protection mechanism, via a crafted application, aka \"Win32k Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0176",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90052",
          "name" : "90052",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-284",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-284",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0177",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0178",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90032",
          "name" : "90032",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035837",
          "name" : "1035837",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-061",
          "name" : "MS16-061",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles free operations, which allows remote attackers to execute arbitrary code via malformed RPC requests, aka \"RPC Network Data Representation Engine Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0179",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89868",
          "name" : "89868",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035825",
          "name" : "1035825",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-057",
          "name" : "MS16-057",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Windows Shell in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted web site, aka \"Windows Shell Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0180",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90028",
          "name" : "90028",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035833",
          "name" : "1035833",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-060",
          "name" : "MS16-060",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles symbolic links, which allows local users to gain privileges via a crafted application, aka \"Windows Kernel Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0181",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90048",
          "name" : "90048",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035843",
          "name" : "1035843",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-066",
          "name" : "MS16-066",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka \"Hypervisor Code Integrity Security Feature Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0182",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89867",
          "name" : "89867",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035824",
          "name" : "1035824",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-056",
          "name" : "MS16-056",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1225",
          "name" : "20160510 Microsoft Windows Journal OOB Write Memory Corruption Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Windows Journal in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal (aka .jnt) file, aka \"Windows Journal Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0183",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_web_apps",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sharepoint_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035819",
          "name" : "1035819",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-054",
          "name" : "MS16-054",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka \"Microsoft Office Graphics RCE Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0184",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89892",
          "name" : "89892",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035823",
          "name" : "1035823",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-055",
          "name" : "MS16-055",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka \"Direct3D Use After Free Vulnerability.\""
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/416.html\">CWE-416: Use After Free</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0185",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90023",
          "name" : "90023",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035832",
          "name" : "1035832",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-277",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-277",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-059",
          "name" : "MS16-059",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39805/",
          "name" : "39805",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka \"Windows Media Center Remote Code Execution Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0186",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90008",
          "name" : "90008",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035821",
          "name" : "1035821",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-338",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-338",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-355",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-355",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-052",
          "name" : "MS16-052",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0191 and CVE-2016-0193."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0187",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "jscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vbscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90011",
          "name" : "90011",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035820",
          "name" : "1035820",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051",
          "name" : "MS16-051",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-053",
          "name" : "MS16-053",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Microsoft (1) JScript 5.8 and (2) VBScript 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0189."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:jscript:5.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:vbscript:5.8:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0188",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90003",
          "name" : "90003",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035820",
          "name" : "1035820",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051",
          "name" : "MS16-051",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing protection mechanism via unspecified vectors, aka \"Internet Explorer Security Feature Bypass.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0189",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "jscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vbscript",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90012",
          "name" : "90012",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035820",
          "name" : "1035820",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051",
          "name" : "MS16-051",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-053",
          "name" : "MS16-053",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40118/",
          "name" : "40118",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.virusbulletin.com/virusbulletin/2017/01/journey-and-evolution-god-mode-2016-cve-2016-0189/",
          "name" : "https://www.virusbulletin.com/virusbulletin/2017/01/journey-and-evolution-god-mode-2016-cve-2016-0189/",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0187."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:jscript:5.8:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:vbscript:5.7:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:microsoft:vbscript:5.8:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0190",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90075",
          "name" : "90075",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035844",
          "name" : "1035844",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-067",
          "name" : "MS16-067",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB disk accesses originate from the user who mounted a disk, which allows local users to read arbitrary files on these disks via RemoteFX requests, aka \"Remote Desktop Protocol Drive Redirection Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0191",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90010",
          "name" : "90010",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035821",
          "name" : "1035821",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-282",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-282",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-052",
          "name" : "MS16-052",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0186 and CVE-2016-0193."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0192",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90007",
          "name" : "90007",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035820",
          "name" : "1035820",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035821",
          "name" : "1035821",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-276",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-276",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051",
          "name" : "MS16-051",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-052",
          "name" : "MS16-052",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Microsoft Browser Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0193",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "edge",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90009",
          "name" : "90009",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035821",
          "name" : "1035821",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-283",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-283",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-052",
          "name" : "MS16-052",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0186 and CVE-2016-0191."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0194",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90004",
          "name" : "90004",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035820",
          "name" : "1035820",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-275",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-275",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051",
          "name" : "MS16-051",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass file permissions and obtain sensitive information via a crafted web site, aka \"Internet Explorer Information Disclosure Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0195",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89901",
          "name" : "89901",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035823",
          "name" : "1035823",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-055",
          "name" : "MS16-055",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka \"Windows Imaging Component Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0196",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90101",
          "name" : "90101",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-278",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-278",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0171, CVE-2016-0173, and CVE-2016-0174."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0197",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "windows_10",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1511",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_rt_8.1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2008",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_server_2012",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  }, {
                    "version_value" : "r2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "windows_vista",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90102",
          "name" : "90102",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035841",
          "name" : "1035841",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-062",
          "name" : "MS16-062",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_7:-:sp1:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0198",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "office",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2010",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "office_compatibility_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2007",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2010",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2013",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_for_mac",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2011",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2016",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "word_viewer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "*",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/89962",
          "name" : "89962",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035819",
          "name" : "1035819",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-054",
          "name" : "MS16-054",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2011:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_for_mac:2016:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-11T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0199",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137533/Microsoft-Internet-Explorer-11-Garbage-Collector-Attribute-Type-Confusion.html",
          "name" : "http://packetstormsecurity.com/files/137533/Microsoft-Internet-Explorer-11-Garbage-Collector-Attribute-Type-Confusion.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Jun/44",
          "name" : "20160618 CVE-2016-0199 / MS16-063: MSIE 11 garbage collector attribute type confusion",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/538706/100/0/threaded",
          "name" : "20160617 CVE-2016-0199 / MS16-063: MSIE 11 garbage collector attribute type confusion",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036096",
          "name" : "1036096",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063",
          "name" : "MS16-063",
          "refsource" : "MS",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39994/",
          "name" : "39994",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1226",
          "name" : "20160614 Microsoft Internet Explorer 11 Garbage Collector Attribute Type Confusion Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0200 and CVE-2016-3211."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-16T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0200",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "microsoft",
            "product" : {
              "product_data" : [ {
                "product_name" : "internet_explorer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036096",
          "name" : "1036096",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-365",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-365",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-063",
          "name" : "MS16-063",
          "refsource" : "MS",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0199 and CVE-2016-3211."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-16T01:59Z",
    "lastModifiedDate" : "2018-10-12T22:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0201",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_network_protection_firmware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/80883",
          "name" : "80883",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034696",
          "name" : "1034696",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21974242",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21974242",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:security_network_protection_firmware:5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:security_network_protection_firmware:5.3.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-18T05:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0202",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_orchestrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000134",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000134",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94578",
          "name" : "94578",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-15T12:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0203",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_orchestrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.01",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "smartcloud_orchestrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000140",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000140",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94440",
          "name" : "94440",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.5.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:smartcloud_orchestrator:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:smartcloud_orchestrator:2.3.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-15T14:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0204",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_orchestrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-601"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93512",
          "name" : "93512",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000124",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000124",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.8,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 4.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-10-16T21:59Z",
    "lastModifiedDate" : "2018-05-02T15:23Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0205",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_orchestrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/109394",
          "name" : "ibm-co-cve20160205-info-disc(109394)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        }, {
          "url" : "https://www-01.ibm.com/support/docview.wss?uid=swg2C4000049",
          "name" : "https://www-01.ibm.com/support/docview.wss?uid=swg2C4000049",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-08-30T16:29Z",
    "lastModifiedDate" : "2019-10-09T23:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0206",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_orchestrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000141",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000141",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94656",
          "name" : "94656",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cloud_orchestrator:2.4.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-15T13:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0207",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "algo_risk_application",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981322",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981322",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/109399",
          "name" : "ibm-algo-cve20160207-clickjacking(109399)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. IBM X-Force ID: 109399."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:algo_risk_application:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "4.9.1",
          "versionEndIncluding" : "5.1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-01-16T19:29Z",
    "lastModifiedDate" : "2018-02-01T20:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0208",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_commerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035239",
          "name" : "1035239",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1JR54988",
          "name" : "JR54988",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21975774",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21975774",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:8.0.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-14T01:59Z",
    "lastModifiedDate" : "2019-09-30T16:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0209",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1034844",
          "name" : "1034844",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21974564",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21974564",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-01-27T05:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0210",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "sterling_b2b_integrator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21981549",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21981549",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/90527",
          "name" : "90527",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_b2b_integrator:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-15T13:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0211",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "db2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "db2_connect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/85979",
          "name" : "85979",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035660",
          "name" : "1035660",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT12462",
          "name" : "IT12462",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT12487",
          "name" : "IT12487",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT12488",
          "name" : "IT12488",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT13350",
          "name" : "IT13350",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979984",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979984",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.1:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.1:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.1:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.2:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.2:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.2:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.3:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.3:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.3:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.3:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.4:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.4:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.4:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.4:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.5:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.5:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.5:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8.0.5:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.1:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.1:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.2:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.2:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.3:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.3:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.4:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.4:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.5:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.8.0.5:*:*:*:unlimited:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.1:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.1:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.1:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.2:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.2:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.2:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.3:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.3:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.3:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.3:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.4:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.4:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.4:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.4:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.5:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.5:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.5:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.5:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.6:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.6:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.6:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.6:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.6:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.7:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.7:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.7:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.7:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5.0.7:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.1:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.1:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.2:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.2:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.3:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.3:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.4:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.4:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.5:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.5:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.6:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.6:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.6:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.7:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.7:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.5.0.7:*:*:*:unlimited:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.1:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.1:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.1:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.2:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.2:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.2:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.3:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.3:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.3:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.3:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.4:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.4:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.4:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.4:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.5:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.5:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.5:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1.0.5:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.1:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.1:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.2:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.2:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.3:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.3:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.4:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.4:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.5:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:10.1.0.5:*:*:*:unlimited:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.1:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.2:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.3:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.4:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.5:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.6:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.7:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.7:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.7:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.7:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.7:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.8:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.8:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.8:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.8:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.8:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.9:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.9:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.9:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.9:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.9:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.10:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.10:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.10:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.10:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.10:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.11:*:*:*:advanced_enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.11:*:*:*:advanced_workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.11:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.11:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7.0.11:*:*:*:workgroup:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.1:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.1:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.1:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.2:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.2:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.2:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.3:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.3:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.3:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.4:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.4:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.4:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.5:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.5:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.5:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.6:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.6:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.6:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.7:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.7:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.7:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.8:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.8:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.8:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.9:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.9:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.9:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.10:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.10:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.10:*:*:*:unlimited:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.11:*:*:*:application_server:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.11:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:db2_connect:9.7.0.11:*:*:*:unlimited:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-28T01:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0212",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_storage_manager_fastback",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_security_vulnerabilities_in_ibm_tivoli_storage_manager_fastback_cve_2016_0212_cve_2016_0213_cve_2016_0216",
          "name" : "http://www.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_security_vulnerabilities_in_ibm_tivoli_storage_manager_fastback_cve_2016_0212_cve_2016_0213_cve_2016_0216",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0213 and CVE-2016-0216."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2016-03-03T19:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0213",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_storage_manager_fastback",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_security_vulnerabilities_in_ibm_tivoli_storage_manager_fastback_cve_2016_0212_cve_2016_0213_cve_2016_0216",
          "name" : "http://www.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_security_vulnerabilities_in_ibm_tivoli_storage_manager_fastback_cve_2016_0212_cve_2016_0213_cve_2016_0216",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0216."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2016-03-03T19:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0214",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21993203",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21993203",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94193",
          "name" : "94193",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way that file would be executed would be through a phishing attack to trick an unsuspecting victim to execute the file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-15T13:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0215",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "db2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979986",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979986",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_enterprise_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:advanced_workgroup_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:connect_application_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:connect_enterprise:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:connect_unlimited:system_i:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:connect_unlimited:system_z:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:enterprise_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:express:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.7:*:*:*:workgroup_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_enterprise_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:advanced_workgroup_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:connect_application_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:connect_enterprise:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:connect_unlimited:system_i:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:connect_unlimited:system_z:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:enterprise_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:express:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.1:*:*:*:workgroup_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_enterprise_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:advanced_workgroup_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:connect_application_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:connect_enterprise:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:connect_unlimited:system_i:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:connect_unlimited:system_z:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:enterprise_server:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:express:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:10.5:*:*:*:workgroup_server:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:db2:9.8:*:*:*:enterprise_server:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-01-16T19:29Z",
    "lastModifiedDate" : "2018-02-05T20:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0216",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_storage_manager_fastback",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.11.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_security_vulnerabilities_in_ibm_tivoli_storage_manager_fastback_cve_2016_0212_cve_2016_0213_cve_2016_0216",
          "name" : "http://www.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_security_vulnerabilities_in_ibm_tivoli_storage_manager_fastback_cve_2016_0212_cve_2016_0213_cve_2016_0216",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0213."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager_fastback:6.1.11.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2016-03-03T17:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0217",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_analytics",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21996417",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21996417",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/95681",
          "name" : "95681",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_analytics:11.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_analytics:11.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_analytics:11.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_analytics:11.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_analytics:11.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-02-01T22:59Z",
    "lastModifiedDate" : "2019-09-30T15:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0218",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/95456",
          "name" : "95456",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21995691",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21995691",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21996417",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21996417",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input.  A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked.  An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-02-01T22:59Z",
    "lastModifiedDate" : "2017-04-06T01:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0219",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_collaborative_lifecycle_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_doors_next_generation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_engineering_lifecycle_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_quality_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_requirements_composer",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_rhapsody_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_software_architect_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-611"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983720",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983720",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/109693",
          "name" : "ibm-rtc-cve20160219-dos(109693)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_requirements_composer:4.0.7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-01-16T19:29Z",
    "lastModifiedDate" : "2018-02-05T15:07Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0221",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91542",
          "name" : "91542",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036221",
          "name" : "1036221",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984323",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984323",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Cognos TM1, as used in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-03T21:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0222",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "maximo_asset_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "maximo_for_government",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "maximo_for_life_sciences",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "maximo_for_nuclear_power",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "maximo_for_oil_and_gas",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "maximo_for_transportation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "maximo_for_utilities",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "smartcloud_control_desk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976949",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976949",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.3:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:smartcloud_control_desk:-:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.1:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.3:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_for_government:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_for_life_sciences:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_for_nuclear_power:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_for_oil_and_gas:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_for_transportation:-:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:maximo_for_utilities:-:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-14T01:59Z",
    "lastModifiedDate" : "2016-03-17T22:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0223",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "forms_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977574",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977574",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110006",
          "name" : "ibm-forms-cve20160223-xss(110006)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_server:4.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_server:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_server:8.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_server:8.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_server:8.2.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-03-15T22:29Z",
    "lastModifiedDate" : "2018-04-09T12:23Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0224",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980989",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980989",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-28T01:59Z",
    "lastModifiedDate" : "2016-06-28T14:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0225",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_commerce",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          }, {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1JR54585",
          "name" : "JR54585",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976623",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976623",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:6.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_commerce:7.0.0.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2019-09-30T16:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0226",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "informix_dynamic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.70.xcn",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035286",
          "name" : "1035286",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21978598",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21978598",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://zerodayinitiative.com/advisories/ZDI-16-208/",
          "name" : "http://zerodayinitiative.com/advisories/ZDI-16-208/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://zerodayinitiative.com/advisories/ZDI-16-209/",
          "name" : "http://zerodayinitiative.com/advisories/ZDI-16-209/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://zerodayinitiative.com/advisories/ZDI-16-210/",
          "name" : "http://zerodayinitiative.com/advisories/ZDI-16-210/",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:informix_dynamic_server:11.70.xcn:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-28T23:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0227",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_process_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.6.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035175",
          "name" : "1035175",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1JR55152",
          "name" : "JR55152",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21978058",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21978058",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.0.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.1:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.2:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.3:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.3:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.0.1.3:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.0:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.0:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.1:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.1:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.1:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.2:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.0.2:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.5.0:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.5.0:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.5.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.2:*:*:*:advanced:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.2:*:*:*:express:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.2:*:*:*:standard:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-03T22:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0228",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-601"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22001952",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22001952",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/97670",
          "name" : "97670",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM X-Force ID: 110236."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-04-17T21:59Z",
    "lastModifiedDate" : "2017-04-21T15:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0229",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980989",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980989",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-28T01:59Z",
    "lastModifiedDate" : "2016-06-28T14:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0230",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "power_hardware_management_console",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91535",
          "name" : "91535",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=nas8N1021387",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=nas8N1021387",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04021",
          "name" : "MB04021",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04022",
          "name" : "MB04022",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04023",
          "name" : "MB04023",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04024",
          "name" : "MB04024",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04025",
          "name" : "MB04025",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04026",
          "name" : "MB04026",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1MB04027",
          "name" : "MB04027",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/069vc/2/MH01635.readme.html",
          "name" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/069vc/2/MH01635.readme.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/069y2/1/MH01636.readme.html",
          "name" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/069y2/1/MH01636.readme.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/06a1r/2/MH01638.readme.html",
          "name" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/06a1r/2/MH01638.readme.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/06a1v/2/MH01639.readme.html",
          "name" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/06a1v/2/MH01639.readme.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/06a2q/1/MH01640.readme.html",
          "name" : "https://delivery04.dhe.ibm.com/sar/CMA/HMA/06a2q/1/MH01640.readme.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.9.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.9.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.9.0:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.1.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.1.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.1.0:sp3:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.2.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.2.0:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.3.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.3.0:sp2:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.3.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.3.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.3.0:sp5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:7.3.0:sp7:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.4.0:sp1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:power_hardware_management_console:8.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "PHYSICAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.8,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-07T14:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0231",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56757",
          "name" : "PI56757",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56758",
          "name" : "PI56758",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56759",
          "name" : "PI56759",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56762",
          "name" : "PI56762",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56763",
          "name" : "PI56763",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56764",
          "name" : "PI56764",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976392",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976392",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-15T23:59Z",
    "lastModifiedDate" : "2016-03-10T21:07Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0232",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56757",
          "name" : "PI56757",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56758",
          "name" : "PI56758",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56759",
          "name" : "PI56759",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56762",
          "name" : "PI56762",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56763",
          "name" : "PI56763",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56764",
          "name" : "PI56764",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976392",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21976392",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.0:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.1:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.2:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.3:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.4:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.5:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.6:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.7:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.8:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.9:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.10:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.11:*:*:*:*:ach_services:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.0:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.1:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.2:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.3:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.4:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.5:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.6:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.7:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.8:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.9:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.10:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.11:*:*:*:*:check_services:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.0:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.1:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.2:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.3:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.4:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.5:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.6:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.7:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.8:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.9:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.10:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:3.0.0.11:*:*:*:*:cps_services:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-15T23:59Z",
    "lastModifiedDate" : "2016-03-10T21:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0233",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980989",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980989",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:8.6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-28T01:59Z",
    "lastModifiedDate" : "2016-06-28T13:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0234",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "openpages_grc_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-613"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21997687",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21997687",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110303",
          "name" : "ibm-openpages-cve20160234-info-disc(110303)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:openpages_grc_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "7.1.0.0",
          "versionEndIncluding" : "7.1.0.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:openpages_grc_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "7.2.0.0",
          "versionEndIncluding" : "7.2.0.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:openpages_grc_platform:7.3.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-08-30T16:29Z",
    "lastModifiedDate" : "2019-10-09T23:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0235",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-798"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981748",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981748",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110326",
          "name" : "ibm-guardian-cve20160235-info-disc(110326)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.2,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.5,
        "impactScore" : 6.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-12T21:29Z",
    "lastModifiedDate" : "2018-04-04T17:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0236",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-77"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93823",
          "name" : "93823",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990372",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990372",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-21T17:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0237",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981631",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981631",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110328",
          "name" : "ibm-guardian-cve20160237-info-disc(110328)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-12T21:29Z",
    "lastModifiedDate" : "2018-04-04T17:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0238",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21989124",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21989124",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/99379",
          "name" : "99379",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110409",
          "name" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110409",
          "refsource" : "MISC",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-07-05T13:29Z",
    "lastModifiedDate" : "2017-07-11T17:07Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0239",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93827",
          "name" : "93827",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988999",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988999",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0240",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93836",
          "name" : "93836",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990232",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990232",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0241",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93828",
          "name" : "93828",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990219",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990219",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0242",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93825",
          "name" : "93825",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990229",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990229",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2017-04-07T23:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0243",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/100572",
          "name" : "100572",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83488",
          "name" : "83488",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI54088",
          "name" : "PI54088",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244."
        }, {
          "lang" : "en",
          "value" : "Appropriate Vendor Advisory Link:  <a href=\"http://www-01.ibm.com/support/docview.wss?uid=swg21976358\">HERE</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2017-09-03T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0244",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI55327",
          "name" : "PI55327",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243."
        }, {
          "lang" : "en",
          "value" : "Appropriate Vendor Advisory Link:  <a href=\"http://www-01.ibm.com/support/docview.wss?uid=swg21976358\">HERE</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:6.1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2016-03-03T16:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0245",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21975358",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56682",
          "name" : "PI56682",
          "refsource" : "AIXAPAR",
          "tags" : [ "Not Applicable" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/611.html\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_portal:8.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-29T11:59Z",
    "lastModifiedDate" : "2017-02-19T06:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0246",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93400",
          "name" : "93400",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990377",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990377",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0247",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93341",
          "name" : "93341",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990368",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990368",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0248",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93137",
          "name" : "93137",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982031",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982031",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-26T04:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0249",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93339",
          "name" : "93339",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990363",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990363",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "8.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:10.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 8.6,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-16T21:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0250",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "infosphere_information_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-611"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977152",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977152",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110510",
          "name" : "ibm-infosphere-cve20160250-info-disc(110510)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "11.3",
          "versionEndExcluding" : "11.3.1.2"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:infosphere_information_server:11.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-12T21:29Z",
    "lastModifiedDate" : "2018-04-09T17:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0252",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "control_center",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "sterling_control_center",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985641",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985641",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:control_center:6.0.0.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_control_center:5.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_control_center:5.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_control_center:5.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_control_center:5.4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_control_center:5.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_control_center:5.4.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.4,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2016-07-08T15:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0253",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110562",
          "name" : "ibm-ftm-cve20160253-xss(110562)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110562."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:ach_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:check_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:cps_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-26T18:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0254",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-611"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22004036",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22004036",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/98971",
          "name" : "98971",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110563",
          "name" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110563",
          "refsource" : "MISC",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-06-07T17:29Z",
    "lastModifiedDate" : "2017-06-14T14:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0255",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22001950",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22001950",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/98336",
          "name" : "98336",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 110564."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:9.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:marketing_platform:10.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-05-05T19:29Z",
    "lastModifiedDate" : "2017-05-12T17:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0259",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_mq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036179",
          "name" : "1036179",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984561",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984561",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and obtain sensitive information via unspecified display commands."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.5,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-26T14:59Z",
    "lastModifiedDate" : "2016-11-30T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0260",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_mq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984564",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984564",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of service (heap memory consumption) by triggering many errors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-29T01:59Z",
    "lastModifiedDate" : "2016-06-30T15:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0261",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "care_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "curam_social_program_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981103",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981103",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/110604",
          "name" : "ibm-curam-cve20160261-xss(110604)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.0:sp2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "6.0.4.0",
          "versionEndIncluding" : "6.0.4.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "6.0.5.0",
          "versionEndIncluding" : "6.0.5.9"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:curam_social_program_management:6.1.1.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:care_management:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-03-12T21:29Z",
    "lastModifiedDate" : "2018-04-09T14:57Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0262",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "maximo_asset_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977828",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977828",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX004, and 7.6.0 before 7.6.0.3 IFIX001 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-14T01:59Z",
    "lastModifiedDate" : "2016-03-16T13:04Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0263",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "general_parallel_file_system_storage_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.29",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "spectrum_scale",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90525",
          "name" : "90525",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036458",
          "name" : "1036458",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=ssg1S1005708",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=ssg1S1005708",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:3.5.0.29:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:spectrum_scale:4.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:spectrum_scale:4.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:spectrum_scale:4.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:spectrum_scale:4.1.1.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:spectrum_scale:4.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:spectrum_scale:4.2.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.0,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-29T01:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0264",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "satellite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_supplementary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "manager_proxy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "openstack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux_enterprise_software_development_kit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_linux_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html",
          "name" : "SUSE-SU-2016:1299",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html",
          "name" : "SUSE-SU-2016:1300",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html",
          "name" : "SUSE-SU-2016:1303",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html",
          "name" : "SUSE-SU-2016:1378",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html",
          "name" : "SUSE-SU-2016:1379",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html",
          "name" : "SUSE-SU-2016:1388",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html",
          "name" : "SUSE-SU-2016:1458",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html",
          "name" : "SUSE-SU-2016:1475",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html",
          "name" : "RHSA-2016:0701",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html",
          "name" : "RHSA-2016:0702",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html",
          "name" : "RHSA-2016:0708",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html",
          "name" : "RHSA-2016:0716",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html",
          "name" : "RHSA-2016:1039",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035953",
          "name" : "1035953",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV84035",
          "name" : "IV84035",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1216",
          "name" : "RHSA-2017:1216",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "6.0.0.0",
          "versionEndExcluding" : "6.0.16.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "6.1.0.0",
          "versionEndExcluding" : "6.1.8.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "7.0.0.0",
          "versionEndExcluding" : "7.0.9.40"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "7.1.0.0",
          "versionEndExcluding" : "7.1.3.40"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "8.0.0.0",
          "versionEndExcluding" : "8.0.3.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:suse_linux_enterprise_server:12:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:suse:manager:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:suse:manager_proxy:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:suse:openstack:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.6,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-24T15:59Z",
    "lastModifiedDate" : "2019-06-24T14:07Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0265",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "campaign",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21986033",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21986033",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/95100",
          "name" : "95100",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Campaign is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:campaign:8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:campaign:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:campaign:9.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:campaign:9.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-02-01T20:59Z",
    "lastModifiedDate" : "2017-02-05T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0266",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "vios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4.22",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92150",
          "name" : "92150",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036467",
          "name" : "1036467",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV86116",
          "name" : "IV86116",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV86117",
          "name" : "IV86117",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV86118",
          "name" : "IV86118",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV86119",
          "name" : "IV86119",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV86120",
          "name" : "IV86120",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV86132",
          "name" : "IV86132",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://aix.software.ibm.com/aix/efixes/security/nettcp_advisory2.asc",
          "name" : "https://aix.software.ibm.com/aix/efixes/security/nettcp_advisory2.asc",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.51:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.4.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.4.22:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-08T01:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0267",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "urbancode_deploy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000151",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000151",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.7,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.1,
        "impactScore" : 4.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-29T01:59Z",
    "lastModifiedDate" : "2016-06-29T17:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0268",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-611"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 110915."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:ach_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:check_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:cps_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-26T18:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0269",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91690",
          "name" : "91690",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985734",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985734",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.6:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.8:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-15T18:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0270",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "client_application_access",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "notes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/96062",
          "name" : "96062",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037795",
          "name" : "1037795",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979604",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979604",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979669",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979669",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979673",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979673",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://github.com/nonce-disrespect/nonce-disrespect",
          "name" : "https://github.com/nonce-disrespect/nonce-disrespect",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://support.citrix.com/article/CTX220329",
          "name" : "https://support.citrix.com/article/CTX220329",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a \"forbidden attack.\" NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:client_application_access:1.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:notes:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:notes:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:notes:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T16:59Z",
    "lastModifiedDate" : "2017-11-15T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0271",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "urbancode_deploy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000150",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000150",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.2,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.5,
        "impactScore" : 6.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2016-07-08T15:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0272",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111052",
          "name" : "ibm-ftm-cve20160272-csrf(111052)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:ach_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:check_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:cps_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.0,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.1,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-26T18:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0273",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_collaborative_lifecycle_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_doors_next_generation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_engineering_lifecycle_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_quality_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_rhapsody_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_software_architect_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94557",
          "name" : "94557",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-30T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0274",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111076",
          "name" : "ibm-ftm-cve20160274-clickjacking(111076)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM X-Force ID: 111076."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:ach_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:check_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:cps_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-26T17:45Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0275",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:ach_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:check_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.2:*:*:*:*:cps_services:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:ach_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:check_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:cps_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-27T16:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0276",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_transaction_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977245",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111084",
          "name" : "ibm-ftm-cve20160276-code-exec(111084)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. IBM X-Force ID: 111084."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:ach_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:check_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:cps_services:*:*",
          "versionStartIncluding" : "3.0.0.0",
          "versionEndIncluding" : "3.0.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 6.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-26T17:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0277",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036091",
          "name" : "1036091",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0278, CVE-2016-0279, and CVE-2016-0301."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-26T14:59Z",
    "lastModifiedDate" : "2019-10-16T12:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0278",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036091",
          "name" : "1036091",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.talosintelligence.com/reports/TALOS-2016-0090/",
          "name" : "http://www.talosintelligence.com/reports/TALOS-2016-0090/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0279, and CVE-2016-0301."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-26T14:59Z",
    "lastModifiedDate" : "2019-10-16T12:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0279",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036091",
          "name" : "1036091",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0301."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-26T14:59Z",
    "lastModifiedDate" : "2019-10-16T12:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0280",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "information_server_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "infosphere_information_governance_catalog",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "infosphere_information_server_business_glossary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92133",
          "name" : "92133",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036418",
          "name" : "1036418",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1JR55452",
          "name" : "JR55452",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981766",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981766",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Patch", "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:information_server_framework:8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:information_server_framework:8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:information_server_framework:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:information_server_framework:11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:information_server_framework:11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:infosphere_information_governance_catalog:11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:infosphere_information_governance_catalog:11.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:infosphere_information_server_business_glossary:8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:infosphere_information_server_business_glossary:9.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-08-08T01:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0281",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "vios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.4",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "aix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://aix.software.ibm.com/aix/efixes/security/mustendd_advisory.asc",
          "name" : "http://aix.software.ibm.com/aix/efixes/security/mustendd_advisory.asc",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92193",
          "name" : "92193",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036481",
          "name" : "1036481",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV80569",
          "name" : "IV80569",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV81357",
          "name" : "IV81357",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV81459",
          "name" : "IV81459",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV82421",
          "name" : "IV82421",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV84184",
          "name" : "IV84184",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:aix:7.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:vios:2.2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:ibm:vios:2.2.3.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-08T01:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0282",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "lotus_inotes",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.6",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94558",
          "name" : "94558",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037383",
          "name" : "1037383",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991722",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991722",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:lotus_inotes:8.5.3.6:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2017-07-28T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0283",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035330",
          "name" : "1035330",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI58003",
          "name" : "PI58003",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21978293",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21978293",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.1:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.3:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.7:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.8:*:*:*:liberty:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-03-19T15:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0284",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_collaborative_lifecycle_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_doors_next_generation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_engineering_lifecycle_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_quality_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_rhapsody_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_software_architect_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-611"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94555",
          "name" : "94555",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-30T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0285",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94550",
          "name" : "94550",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted field."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-30T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0286",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_business_service_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986852",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986852",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111234",
          "name" : "ibm-tivoli-cve20160286-info-disc(111234)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obtain administrator passwords by leveraging unspecified privileges. BM X-Force ID: 111234."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_business_service_manager:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_business_service_manager:6.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-03-09T19:29Z",
    "lastModifiedDate" : "2018-03-26T17:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0287",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "i_access",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91706",
          "name" : "91706",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=nas8N1021418",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=nas8N1021418",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1SI60523",
          "name" : "SI60523",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "https://www.tenable.com/security/research/tra-2016-18",
          "name" : "https://www.tenable.com/security/research/tra-2016-18",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:i_access:7.1:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2017-11-03T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0288",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_appscan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035927",
          "name" : "1035927",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980055",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980055",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/611.html\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:8.7.0.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:8.7.0.1:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:8.8.0.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.0.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.0.1:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.1.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.1.1:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.2.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.2.1:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.3.0:*:*:*:standard:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_appscan:9.0.3.1:*:*:*:standard:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-01T15:59Z",
    "lastModifiedDate" : "2016-11-30T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0289",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "maximo_asset_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979519",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979519",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-05T17:59Z",
    "lastModifiedDate" : "2016-04-06T12:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0291",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-78"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985748",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985748",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111302",
          "name" : "ibm-mdm-cve20160291-command-injection(111302)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "9.1",
          "versionEndExcluding" : "9.1.8"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "9.2",
          "versionEndExcluding" : "9.2.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-28T17:29Z",
    "lastModifiedDate" : "2018-03-17T10:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0292",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985907",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985907",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by reading a report."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-30T17:59Z",
    "lastModifiedDate" : "2017-06-09T13:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0293",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92593",
          "name" : "92593",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985743",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985743",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2.7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0.8:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-09-01T01:59Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0295",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985830",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985830",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111363",
          "name" : "ibm-mdm-cve20160295-csrf(111363)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "9.5",
          "versionEndExcluding" : "9.5.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-02-28T17:29Z",
    "lastModifiedDate" : "2018-03-16T17:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0296",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-532"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21993213",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21993213",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94213",
          "name" : "94213",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-01T20:59Z",
    "lastModifiedDate" : "2017-02-05T20:37Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0297",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21993214",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21993214",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94188",
          "name" : "94188",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-01T20:59Z",
    "lastModifiedDate" : "2017-02-05T20:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0298",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981749",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981749",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-29T01:59Z",
    "lastModifiedDate" : "2016-06-29T16:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0299",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981155",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981155",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111382",
          "name" : "ibm-tririga-cve20160299-info-disc(111382)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a database query. IBM X-Force ID: 111382."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.3.0.0",
          "versionEndExcluding" : "3.3.2.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.4.0.0",
          "versionEndExcluding" : "3.4.2.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-28T17:29Z",
    "lastModifiedDate" : "2018-03-17T10:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0300",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979760",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979760",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111412",
          "name" : "ibm-tririga-cve20160300-sec-bypass(111412)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-02T21:29Z",
    "lastModifiedDate" : "2018-02-14T15:24Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0301",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036091",
          "name" : "1036091",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983292",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0279."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-26T14:59Z",
    "lastModifiedDate" : "2019-10-16T12:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0303",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_integrated_portal",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0.15",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981591",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981591",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_integrated_portal:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.2.0.0",
          "versionEndIncluding" : "2.2.0.15"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-02-02T21:29Z",
    "lastModifiedDate" : "2018-02-15T15:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0304",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "domino",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983328",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983328",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.3.6:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.2.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.1.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:8.5.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-29T01:59Z",
    "lastModifiedDate" : "2019-10-16T12:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0305",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "connections",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21986770",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21986770",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92436",
          "name" : "92436",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-10T02:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0306",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/85978",
          "name" : "85978",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56190",
          "name" : "PI56190",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979231",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979231",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-17T14:08Z",
    "lastModifiedDate" : "2016-11-28T19:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0307",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "connections",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21986770",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21986770",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92440",
          "name" : "92440",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-10T02:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0308",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "connections",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21986770",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21986770",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92439",
          "name" : "92439",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-10T02:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0310",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "connections",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21988338",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21988338",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92437",
          "name" : "92437",
          "refsource" : "BID",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-02-08T22:59Z",
    "lastModifiedDate" : "2017-02-10T02:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0311",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_business_service_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986853",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986853",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111480",
          "name" : "ibm-tivoli-cve20160311-xss(111480)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        }, {
          "url" : "https://www.ibm.com/blogs/psirt/ibm-security-bulletin-cross-site-scripting-vulnerability-in-tivoli-business-service-manager-cve-2016-0311/",
          "name" : "https://www.ibm.com/blogs/psirt/ibm-security-bulletin-cross-site-scripting-vulnerability-in-tivoli-business-service-manager-cve-2016-0311/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111480."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_business_service_manager:6.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_business_service_manager:6.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-02-02T21:29Z",
    "lastModifiedDate" : "2018-02-14T16:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0312",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979762",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979762",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111486",
          "name" : "ibm-tririga-cve20160312-info-disc(111486)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. IBM X-Force ID: 111486."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.3.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-02T21:29Z",
    "lastModifiedDate" : "2018-02-14T15:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0313",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2016-07-08T15:21Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0314",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91697",
          "name" : "91697",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0315",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2016-07-08T17:07Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0316",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92472",
          "name" : "92472",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-11-25T20:59Z",
    "lastModifiedDate" : "2016-11-28T23:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0317",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92463",
          "name" : "92463",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-11-25T20:59Z",
    "lastModifiedDate" : "2016-11-29T00:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0318",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92466",
          "name" : "92466",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.0,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-25T20:59Z",
    "lastModifiedDate" : "2016-11-29T00:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0319",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92475",
          "name" : "92475",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983137",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-25T20:59Z",
    "lastModifiedDate" : "2016-11-29T17:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0320",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "urbancode_deploy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000222",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg2C1000222",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/95974",
          "name" : "95974",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-01T22:59Z",
    "lastModifiedDate" : "2017-02-13T19:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0321",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "personal_communications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91751",
          "name" : "91751",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT12006",
          "name" : "IT12006",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981692",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981692",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:12.0.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:personal_communications:6.0.16:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.2,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-17T22:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0322",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "connections",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1LO88783",
          "name" : "LO88783",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982611",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982611",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:4.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:connections:5.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-06-30T01:59Z",
    "lastModifiedDate" : "2016-06-30T13:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0323",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bluemix",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979682",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21979682",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bluemix:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-17T14:08Z",
    "lastModifiedDate" : "2016-05-19T14:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0324",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_virtual_appliance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-77"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111640",
          "name" : "ibm-spim-cve20160324-command-injection(111640)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-01-12T17:29Z",
    "lastModifiedDate" : "2018-01-29T13:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0325",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-78"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94539",
          "name" : "94539",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 allow remote authenticated users to execute arbitrary OS commands via a crafted request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 6.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0326",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_collaborative_lifecycle_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_quality_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-77"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93824",
          "name" : "93824",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989735",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989735",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted \"HTML request.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0327",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_virtual_appliance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111643",
          "name" : "ibm-sim-cve20160327-command-injection(111643)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-01-12T17:29Z",
    "lastModifiedDate" : "2018-01-29T13:35Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0328",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_guardium_database_activity_monitor",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.01",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-77"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93402",
          "name" : "93402",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990226",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21990226",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.01:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_guardium_database_activity_monitor:10.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0329",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "emptoris_sourcing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-601"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982629",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982629",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111692",
          "name" : "ibm-emptoris-cve20160329-url-redirect(111692)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 111692."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:emptoris_sourcing:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0.0",
          "versionEndIncluding" : "10.1.0.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-02-02T21:29Z",
    "lastModifiedDate" : "2018-02-16T16:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0330",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_adapter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-255"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036255",
          "name" : "1036255",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the password algorithm."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 7.3,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-15T18:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0331",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_collaborative_lifecycle_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92840",
          "name" : "92840",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036814",
          "name" : "1036814",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989899",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989899",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-09-12T10:59Z",
    "lastModifiedDate" : "2017-07-30T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0332",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_virtual_appliance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111695",
          "name" : "ibm-sim-cve20160332-brute-force(111695)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-01-12T17:29Z",
    "lastModifiedDate" : "2018-01-29T13:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0335",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111736",
          "name" : "ibm-sim-cve20160335-csrf(111736)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-01-12T17:29Z",
    "lastModifiedDate" : "2018-01-29T13:07Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0336",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981438",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111737",
          "name" : "ibm-sim-cve20160336-xss(111737)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager:7.0.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-01-12T17:29Z",
    "lastModifiedDate" : "2018-01-29T13:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0338",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_adapter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036255",
          "name" : "1036255",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.2,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-15T18:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0339",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_adapter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91689",
          "name" : "91689",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036255",
          "name" : "1036255",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of \"traffic records.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.6,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-15T18:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0340",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_adapter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91692",
          "name" : "91692",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036255",
          "name" : "1036255",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.4,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-15T18:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0341",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "b2b_advanced_communications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "multi-enterprise_integration_gateway",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT14835",
          "name" : "IT14835",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981462",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981462",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:b2b_advanced_communications:1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:b2b_advanced_communications:1.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:b2b_advanced_communications:1.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:b2b_advanced_communications:1.0.0.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:multi-enterprise_integration_gateway:1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-15T01:59Z",
    "lastModifiedDate" : "2016-05-19T16:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0342",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980252",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980252",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111783",
          "name" : "ibm-tririga-cve20160342-info-disc(111783)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to read or modify arbitrary reports by leveraging an incorrect grant of access. IBM X-Force ID: 111783."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.3.0.0",
          "versionEndExcluding" : "3.3.2.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.4.0.0",
          "versionEndExcluding" : "3.4.2.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-02T21:29Z",
    "lastModifiedDate" : "2018-02-15T18:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0343",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980229",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980229",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111784",
          "name" : "ibm-tririga-cve20160343-info-disc(111784)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 111784."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.3.0.0",
          "versionEndExcluding" : "3.3.2.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.4.0.0",
          "versionEndExcluding" : "3.4.2.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-09T18:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0344",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://exchange.xforce.ibmcloud.com/vulnerabilities/111785",
          "name" : "ibm-tririga-cve20160344-xss(111785)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980234",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980234",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111785."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.3.0.0",
          "versionEndExcluding" : "3.3.2.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.4.0.0",
          "versionEndIncluding" : "3.4.2.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-09T18:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0345",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://exchange.xforce.ibmcloud.com/vulnerabilities/111786",
          "name" : "ibm-tririga-cve20160345-info-disc(111786)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980233",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980233",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.3.0.0",
          "versionEndExcluding" : "3.3.2.6"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "3.4.0.0",
          "versionEndExcluding" : "3.4.2.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-09T18:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0346",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/85864",
          "name" : "85864",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036221",
          "name" : "1036221",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984323",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984323",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence 10.2 before IF20, 10.2.1 before IF17, 10.2.1.1 before IF16, 10.2.2 before IF12, and 10.1.1 before IF19 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_business_intelligence:10.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-03T21:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0348",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980237",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980237",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111813",
          "name" : "ibm-tririga-cve20160348-csrf(111813)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.0,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.1,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-09T18:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0349",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_process_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1036185",
          "name" : "1036185",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1JR55701",
          "name" : "JR55701",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981094",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981094",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:business_process_manager:8.5.7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-30T01:59Z",
    "lastModifiedDate" : "2016-11-30T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0350",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "jazz_reporting_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983147",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0313."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:jazz_reporting_service:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-08T01:59Z",
    "lastModifiedDate" : "2016-07-08T17:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0351",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_virtual_appliance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989198",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989198",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111890",
          "name" : "ibm-sim-cve20160351-info-disc(111890)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-13T15:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0353",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_privileged_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94543",
          "name" : "94543",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988706",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988706",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_privileged_identity_manager:2.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0354",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "sametime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-434"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22006439",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22006439",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/100599",
          "name" : "100599",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1039231",
          "name" : "1039231",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111893",
          "name" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111893",
          "refsource" : "MISC",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.1,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-08-29T18:29Z",
    "lastModifiedDate" : "2017-09-07T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0355",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "sametime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22006439",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22006439",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/100599",
          "name" : "100599",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1039231",
          "name" : "1039231",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111894",
          "name" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111894",
          "refsource" : "MISC",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-08-29T18:29Z",
    "lastModifiedDate" : "2017-09-07T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0356",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "sametime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22006439",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22006439",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/100599",
          "name" : "100599",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1039231",
          "name" : "1039231",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111895",
          "name" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111895",
          "refsource" : "MISC",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-08-29T18:29Z",
    "lastModifiedDate" : "2017-09-07T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0357",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_adapter",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/87528",
          "name" : "87528",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036255",
          "name" : "1036255",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985736",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_adapter:7.0.1.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-15T18:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0358",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "sametime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22006441",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22006441",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/100572",
          "name" : "100572",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111928",
          "name" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/111928",
          "refsource" : "MISC",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:8.5.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sametime:9.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-08-29T21:29Z",
    "lastModifiedDate" : "2017-09-03T13:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0359",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91484",
          "name" : "91484",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036184",
          "name" : "1036184",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI58918",
          "name" : "PI58918",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982526",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982526",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL."
        }, {
          "lang" : "en",
          "value" : "<a href=\"https://cwe.mitre.org/data/definitions/93.html\">CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-03T21:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0360",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_mq_jms",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-502"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/95317",
          "name" : "95317",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037561",
          "name" : "1037561",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983457",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983457",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq_jms:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq_jms:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq_jms:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq_jms:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq_jms:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-15T19:59Z",
    "lastModifiedDate" : "2017-07-27T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0361",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "general_parallel_file_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/90550",
          "name" : "90550",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036455",
          "name" : "1036455",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986595",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986595",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:3.5.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system:4.1.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-08T01:59Z",
    "lastModifiedDate" : "2017-09-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0362",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980749",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980749",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service."
        }, {
          "lang" : "en",
          "value" : "<a href=\"https://cwe.mitre.org/data/definitions/918.html\">CWE-918: Server-Side Request Forgery (SSRF)</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "CHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.7,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.1,
        "impactScore" : 4.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-01T01:59Z",
    "lastModifiedDate" : "2016-08-11T13:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0363",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "satellite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_supplementary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux_enterprise_module_for_legacy_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_linux_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_linux_enterprise_software_development_kit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_manager_proxy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_openstack_cloud",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html",
          "name" : "SUSE-SU-2016:1299",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html",
          "name" : "SUSE-SU-2016:1300",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html",
          "name" : "SUSE-SU-2016:1303",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html",
          "name" : "SUSE-SU-2016:1378",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html",
          "name" : "SUSE-SU-2016:1379",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html",
          "name" : "SUSE-SU-2016:1388",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html",
          "name" : "SUSE-SU-2016:1458",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html",
          "name" : "SUSE-SU-2016:1475",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html",
          "name" : "RHSA-2016:0701",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html",
          "name" : "RHSA-2016:0702",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html",
          "name" : "RHSA-2016:0708",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html",
          "name" : "RHSA-2016:0716",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html",
          "name" : "RHSA-2016:1039",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Apr/20",
          "name" : "20160405 Re: [SE-2012-01] Broken security fix in IBM Java 7/8",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Apr/3",
          "name" : "20160404 [SE-2012-01] Broken security fix in IBM Java 7/8",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf",
          "name" : "http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/85895",
          "name" : "85895",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035953",
          "name" : "1035953",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IX90172",
          "name" : "IX90172",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1216",
          "name" : "RHSA-2017:1216",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_module_for_legacy_software:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp2:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp3:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_manager:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_manager_proxy:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_openstack_cloud:5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "6.0.0.0",
          "versionEndExcluding" : "6.0.16.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "6.1.0.0",
          "versionEndExcluding" : "6.1.8.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "7.0.0.0",
          "versionEndExcluding" : "7.0.9.40"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "7.1.0.0",
          "versionEndExcluding" : "7.1.3.40"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "8.0.0.0",
          "versionEndExcluding" : "8.0.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-03T14:59Z",
    "lastModifiedDate" : "2019-06-24T14:25Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0364",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "urbancode_deploy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000152",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000152",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-01T01:59Z",
    "lastModifiedDate" : "2016-07-01T13:55Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0365",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "urbancode_deploy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91526",
          "name" : "91526",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000149",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000149",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.0.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.1.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:6.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-01T01:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0366",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_privileged_identity_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986260",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986260",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/112071",
          "name" : "ibm-sim-cve20160366-weak-security(112071)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_privileged_identity_manager:2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-12T18:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0367",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "security_identity_manager_virtual_appliance",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989198",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21989198",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/112072",
          "name" : "ibm-sim-cve20160367-info-disc(112072)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:security_identity_manager_virtual_appliance:7.0.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-12T18:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0369",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "forms_experience_builder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-611"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988727",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988727",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/112088",
          "name" : "ibm-forms-cve20160369-info-disc(112088)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-02-21T16:29Z",
    "lastModifiedDate" : "2018-03-17T10:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0370",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "forms_experience_builder",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92471",
          "name" : "92471",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1LO88449",
          "name" : "LO88449",
          "refsource" : "AIXAPAR",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1LO88451",
          "name" : "LO88451",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988726",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988726",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.6.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:forms_experience_builder:8.6.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-01T01:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0371",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tivoli_storage_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "6.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3.2.5",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "6.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4.3.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "7.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.6.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94148",
          "name" : "94148",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985114",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985114",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:7.1.0.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "7.1.6.2"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:6.4.0.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "6.4.3.3"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:6.3.0.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "6.3.2.5"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "6.1"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "6.2"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:tivoli_storage_manager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "5.5"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:oracle:solaris:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-01T21:59Z",
    "lastModifiedDate" : "2017-02-15T13:54Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0372",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "rational_collaborative_lifecycle_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_doors_next_generation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_engineering_lifecycle_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_quality_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_rhapsody_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_software_architect_design_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "rational_team_concert",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/94541",
          "name" : "94541",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21991478",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Team Concert 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational DOORS Next Generation 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Engineering Lifecycle Manager 4.x before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Rhapsody Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; and Rational Software Architect Design Manager 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_team_concert:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_quality_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_software_architect_design_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:3.0.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_collaborative_lifecycle_management:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_engineering_lifecycle_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_rhapsody_design_manager:6.0.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:rational_doors_next_generation:6.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0373",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "urbancode_deploy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.201",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-285"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg2C1000219",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/112119",
          "name" : "ibm-ucd-cve20160373-info-disc(112119)",
          "refsource" : "XF",
          "tags" : [ "VDB Entry", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:urbancode_deploy:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "6.0",
          "versionEndIncluding" : "6.2.2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-08-30T16:29Z",
    "lastModifiedDate" : "2019-10-09T23:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0374",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981729",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981729",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users to gain privileges for application modification via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-01T01:59Z",
    "lastModifiedDate" : "2016-07-01T17:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0375",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "messagesight",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT15674",
          "name" : "IT15674",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT15743",
          "name" : "IT15743",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985064",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985064",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:1.2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:messagesight:2.0.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-01T01:59Z",
    "lastModifiedDate" : "2016-07-08T15:22Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0376",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "java_sdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.8.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.3.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "satellite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_supplementary",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "novell",
            "product" : {
              "product_data" : [ {
                "product_name" : "suse_linux_enterprise_module_for_legacy_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_linux_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_linux_enterprise_software_development_kit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_manager_proxy",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "suse_openstack_cloud",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html",
          "name" : "SUSE-SU-2016:1299",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html",
          "name" : "SUSE-SU-2016:1300",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html",
          "name" : "SUSE-SU-2016:1303",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html",
          "name" : "SUSE-SU-2016:1378",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html",
          "name" : "SUSE-SU-2016:1379",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html",
          "name" : "SUSE-SU-2016:1388",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html",
          "name" : "SUSE-SU-2016:1458",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html",
          "name" : "SUSE-SU-2016:1475",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html",
          "name" : "RHSA-2016:0701",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html",
          "name" : "RHSA-2016:0702",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html",
          "name" : "RHSA-2016:0708",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html",
          "name" : "RHSA-2016:0716",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html",
          "name" : "RHSA-2016:1039",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Apr/43",
          "name" : "20160412 [SE-2012-01] Yet another broken security fix in IBM Java 7/8",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.security-explorations.com/materials/SE-2012-01-IBM-5.pdf",
          "name" : "http://www.security-explorations.com/materials/SE-2012-01-IBM-5.pdf",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/538066/100/100/threaded",
          "name" : "20160412 [SE-2012-01] Yet another broken security fix in IBM Java 7/8",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/89192",
          "name" : "89192",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035953",
          "name" : "1035953",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IX90171",
          "name" : "IX90171",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1216",
          "name" : "RHSA-2017:1216",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/502.html\" rel=\"nofollow\">CWE-502: Deserialization of Untrusted Data</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_module_for_legacy_software:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp2:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp3:*:*:ltss:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_linux_enterprise_software_development_kit:12.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_manager:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_manager_proxy:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:novell:suse_openstack_cloud:5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "6.0.0.0",
          "versionEndExcluding" : "6.0.16.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "6.1.0.0",
          "versionEndExcluding" : "6.1.8.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "7.0.0.0",
          "versionEndExcluding" : "7.0.9.40"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "7.1.0.0",
          "versionEndExcluding" : "7.1.3.40"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*",
          "versionStartIncluding" : "8.0.0.0",
          "versionEndExcluding" : "8.0.3.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 4.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-03T14:59Z",
    "lastModifiedDate" : "2019-06-24T16:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0377",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92514",
          "name" : "92514",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036653",
          "name" : "1036653",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI56917",
          "name" : "PI56917",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980645",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980645",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-10-22T03:59Z",
    "lastModifiedDate" : "2017-08-16T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0378",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "16.0.0.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93143",
          "name" : "93143",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI54459",
          "name" : "PI54459",
          "refsource" : "AIXAPAR",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981529",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981529",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*",
          "versionEndIncluding" : "16.0.0.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-11-24T19:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0379",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_mq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-19"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/93146",
          "name" : "93146",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984565",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984565",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:7.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_mq:8.0.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 3.1,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-26T04:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0380",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "sterling_connect:direct",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92336",
          "name" : "92336",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IT14769",
          "name" : "IT14769",
          "refsource" : "AIXAPAR",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988278",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21988278",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.1.0.0:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.1.0.1:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.1.0.2:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.1.0.3:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.1.0.4:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.2.0.0:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.2.0.1:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.2.0.2:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.2.0.3:*:*:*:*:unix:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:sterling_connect\\:direct:4.2.0.4:*:*:*:*:unix:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-08T01:59Z",
    "lastModifiedDate" : "2020-06-25T19:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0381",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_tm1",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.2.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securitytracker.com/id/1035930",
          "name" : "1035930",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981936",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981936",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_tm1:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.2.2"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-15T01:59Z",
    "lastModifiedDate" : "2016-12-01T03:02Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0382",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tealeaf_consumer_experience",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg22000590",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg22000590",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/98301",
          "name" : "98301",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID: 112356."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:8.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:9.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tealeaf_consumer_experience:9.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-05-03T17:59Z",
    "lastModifiedDate" : "2017-05-12T17:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0385",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          }, {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92505",
          "name" : "92505",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036654",
          "name" : "1036654",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI60026",
          "name" : "PI60026",
          "refsource" : "AIXAPAR",
          "tags" : [ "Not Applicable" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982588",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982588",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:7.0.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.0.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.0.2:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.1:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:-:liberty_profile:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:9.0.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.1,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-01T10:59Z",
    "lastModifiedDate" : "2017-08-16T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0386",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV83657",
          "name" : "IV83657",
          "refsource" : "AIXAPAR",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to hijack the authentication of administrators for requests that delete employees."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.0,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.1,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-02T14:59Z",
    "lastModifiedDate" : "2016-07-06T11:52Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0387",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "tririga_application_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981740",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981740",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.3.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:tririga_application_platform:3.5.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-02T14:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0389",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.5.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91515",
          "name" : "91515",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI62052",
          "name" : "PI62052",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982012",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982012",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.3:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.5:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.6:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.7:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.8:*:*:*:liberty:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_application_server:8.5.5.9:*:*:*:liberty:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-07T14:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0390",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "algo_one",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981321",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21981321",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:algo_one:4.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:algo_one:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:algo_one:5.1.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-05-15T01:59Z",
    "lastModifiedDate" : "2016-05-16T14:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0391",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "watson_developer_cloud",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982615",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21982615",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:ibm:watson_developer_cloud:-:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:a:ibm:bluemix:-:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-02T14:59Z",
    "lastModifiedDate" : "2016-07-07T18:03Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0392",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "elastic_storage_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "general_parallel_file_system_storage_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137373/IBM-GPFS-Spectrum-Scale-Command-Injection.html",
          "name" : "http://packetstormsecurity.com/files/137373/IBM-GPFS-Spectrum-Scale-Command-Injection.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/538620/100/0/threaded",
          "name" : "20160607 [CVE-2016-0392] IBM GPFS / Spectrum Scale Command Injection",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91082",
          "name" : "91082",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036458",
          "name" : "1036458",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=ssg1S1005875",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=ssg1S1005875",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IV84206",
          "name" : "IV84206",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:2.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:2.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:2.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:2.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:2.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:2.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:3.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:elastic_storage_server:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:general_parallel_file_system_storage_server:2.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-19T20:59Z",
    "lastModifiedDate" : "2018-10-09T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0393",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "maximo_asset_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/91744",
          "name" : "91744",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986053",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21986053",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-17T22:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0394",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "integration_bus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "websphere_message_broker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-275"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21985013",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21985013",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94577",
          "name" : "94577",
          "refsource" : "BID",
          "tags" : [ "Technical Description", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:integration_bus:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:integration_bus:9.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:integration_bus:9.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:integration_bus:10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_message_broker:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-01T20:59Z",
    "lastModifiedDate" : "2017-02-07T19:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0396",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_platform",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-77"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.ibm.com/support/docview.wss?uid=swg21993206",
          "name" : "http://www.ibm.com/support/docview.wss?uid=swg21993206",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/94155",
          "name" : "94155",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_platform:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-02-01T20:59Z",
    "lastModifiedDate" : "2017-02-07T19:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0397",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "bigfix_webreports",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/92467",
          "name" : "92467",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985907",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21985907",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_webreports:9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_webreports:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_webreports:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:bigfix_webreports:9.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-30T17:59Z",
    "lastModifiedDate" : "2016-11-28T19:53Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0398",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "cognos_analytics",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977070",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21977070",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "IBM Cognos Analytics (CA) 11.0 before 11.0.2 allows remote attackers to conduct content-spoofing attacks via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:cognos_analytics:11.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-02T14:59Z",
    "lastModifiedDate" : "2016-07-05T23:51Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0399",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "maximo_asset_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.6.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984134",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21984134",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.9 IFIX007, and 7.6 before 7.6.0.5 FP005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.5.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:maximo_asset_management:7.6.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-02T14:59Z",
    "lastModifiedDate" : "2016-07-06T11:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0400",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "websphere_extreme_scale",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.6.0.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI60897",
          "name" : "PI60897",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1PI60898",
          "name" : "PI60898",
          "refsource" : "AIXAPAR",
          "tags" : [ ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983036",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=swg21983036",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40039/",
          "name" : "40039",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL."
        }, {
          "lang" : "en",
          "value" : "<a href=\"https://cwe.mitre.org/data/definitions/93.html\">CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:7.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:websphere_extreme_scale:8.6.0.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-07-02T14:59Z",
    "lastModifiedDate" : "2017-09-03T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0401",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect integrity via unknown vectors related to Scheduler, a different vulnerability than CVE-2016-0429."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0402",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html",
          "name" : "SUSE-SU-2016:0256",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html",
          "name" : "openSUSE-SU-2016:0263",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html",
          "name" : "SUSE-SU-2016:0265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html",
          "name" : "openSUSE-SU-2016:0268",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html",
          "name" : "SUSE-SU-2016:0269",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html",
          "name" : "openSUSE-SU-2016:0270",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html",
          "name" : "openSUSE-SU-2016:0272",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html",
          "name" : "openSUSE-SU-2016:0279",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0049.html",
          "name" : "RHSA-2016:0049",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0050.html",
          "name" : "RHSA-2016:0050",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0053.html",
          "name" : "RHSA-2016:0053",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0054.html",
          "name" : "RHSA-2016:0054",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0055.html",
          "name" : "RHSA-2016:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0056.html",
          "name" : "RHSA-2016:0056",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0057.html",
          "name" : "RHSA-2016:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0067.html",
          "name" : "RHSA-2016:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3458",
          "name" : "DSA-3458",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3465",
          "name" : "DSA-3465",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81096",
          "name" : "81096",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034715",
          "name" : "1034715",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2884-1",
          "name" : "USN-2884-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2885-1",
          "name" : "USN-2885-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-14",
          "name" : "GLSA-201603-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vectors related to Networking."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_66:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0403",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB Utilities."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0404",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Identity Federation component in Oracle Fusion Middleware 11.1.2.2 allows remote attackers to affect integrity via vectors related to Admin."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0405",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_and_sun_systems_product_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4 allows local users to affect confidentiality via vectors related to Cluster Manageability and Serviceability."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_and_sun_systems_product_suite:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_and_sun_systems_product_suite:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0406",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via vectors related to Libc."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0407",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_human_capital_management_human_resources",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusion HR Talent Integration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0408",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 through 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to the Activity Guide sub-component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0409",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Security."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-09T18:20Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0410",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0411",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1 and 11.2.0.4 allows local users to affect confidentiality, integrity, and availability via vectors related to Agent Next Gen."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0412",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_supply_chain_management_eprocurement",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise SCM eProcurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Manage Requisition Status."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_eprocurement:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_eprocurement:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-09T18:20Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0413",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Identity Federation component in Oracle Fusion Middleware 11.1.1.7 allows remote authenticated users to affect integrity via vectors related to Federation protocol support."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.7:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0414",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0418."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0415",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to UI Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0416",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to System Archive Utility."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0417",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris_cluster",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.2 allows local users to affect confidentiality, integrity, and availability via vectors related to HA for MySQL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:solaris_cluster:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:solaris_cluster:4.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0418",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0414."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 8.5,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0419",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0431."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0420",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jd_edwards_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/138509/JD-Edwards-9.1-EnterpriseOne-Server-Create-Users.html",
          "name" : "http://packetstormsecurity.com/files/138509/JD-Edwards-9.1-EnterpriseOne-Server-Create-Users.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Aug/126",
          "name" : "20160825 Onapsis Security Advisory ONAPSIS-2016-011: JD Edwards Server Manager Create users",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034722",
          "name" : "1034722",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.onapsis.com/research/security-advisories/jd-edwards-server-manager-create-user",
          "name" : "https://www.onapsis.com/research/security-advisories/jd-edwards-server-manager-create-user",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via unknown vectors related to Monitoring and Diagnostics."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2018-02-20T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0421",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jd_edwards_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/138508/JD-Edwards-9.1-EnterpriseOne-Server-Manager-Shutdown.html",
          "name" : "http://packetstormsecurity.com/files/138508/JD-Edwards-9.1-EnterpriseOne-Server-Manager-Shutdown.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Aug/125",
          "name" : "20160825 Onapsis Security Advisory ONAPSIS-2016-010: JD Edwards Server Manager Shutdown",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034722",
          "name" : "1034722",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.onapsis.com/research/security-advisories/jd-edwards-server-manager-shutdown",
          "name" : "https://www.onapsis.com/research/security-advisories/jd-edwards-server-manager-shutdown",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Monitoring and Diagnostics SEC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2018-02-20T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0422",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jd_edwards_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/138507/JD-Edwards-9.1-EnterpriseOne-Server-JDENet-Password-Disclosure.html",
          "name" : "http://packetstormsecurity.com/files/138507/JD-Edwards-9.1-EnterpriseOne-Server-JDENet-Password-Disclosure.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Aug/124",
          "name" : "20160825 Onapsis Security Advisory ONAPSIS-2016-009: JD Edwards JDENet Password Disclosure",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034722",
          "name" : "1034722",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.onapsis.com/research/security-advisories/jd-edwards-jdenet-password-disclosure",
          "name" : "https://www.onapsis.com/research/security-advisories/jd-edwards-jdenet-password-disclosure",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2016-0424."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2018-02-20T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0423",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jd_edwards_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/138512/JD-Edwards-9.1-EnterpriseOne-Server-JDENET-Denial-Of-Service.html",
          "name" : "http://packetstormsecurity.com/files/138512/JD-Edwards-9.1-EnterpriseOne-Server-JDENET-Denial-Of-Service.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Aug/128",
          "name" : "20160825 Onapsis Security Advisory ONAPSIS-2016-014: JD Edwards JDENET function DoS",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034722",
          "name" : "1034722",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.onapsis.com/research/security-advisories/jd-edwards-jdenet-end-file-dos",
          "name" : "https://www.onapsis.com/research/security-advisories/jd-edwards-jdenet-end-file-dos",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Enterprise Infrastructure SEC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 9.5,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2018-02-20T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0424",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jd_edwards_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/138510/JD-Edwards-9.1-EnterpriseOne-Server-Denial-Of-Service.html",
          "name" : "http://packetstormsecurity.com/files/138510/JD-Edwards-9.1-EnterpriseOne-Server-Denial-Of-Service.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Aug/127",
          "name" : "20160825 Onapsis Security Advisory ONAPSIS-2016-012: JD Edwards JDENET function DoS",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034722",
          "name" : "1034722",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.onapsis.com/research/security-advisories/jd-edwards-jdenet-type-8-dos",
          "name" : "https://www.onapsis.com/research/security-advisories/jd-edwards-jdenet-type-8-dos",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2016-0422."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.1
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2018-02-20T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0425",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jd_edwards_products",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/138511/JD-Edwards-9.1-EnterpriseOne-Server-Password-Disclosure.html",
          "name" : "http://packetstormsecurity.com/files/138511/JD-Edwards-9.1-EnterpriseOne-Server-Password-Disclosure.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Aug/129",
          "name" : "20160825 Onapsis Security Advisory ONAPSIS-2016-00171: JD Edwards Server Manager Password Disclosure",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034722",
          "name" : "1034722",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Monitoring and Diagnostics."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jd_edwards_products:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2018-02-20T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0426",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality and availability via unknown vectors related to Solaris Kernel Zones."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0427",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0428",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Verified Boot."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0429",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect integrity via unknown vectors related to Scheduler, a different vulnerability than CVE-2016-0401."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0430",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect confidentiality via vectors related to SSL support, a different vulnerability than CVE-2016-0439."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0431",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0419."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 1.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0432",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6013, CVE-2015-6014, and CVE-2015-6015."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:8.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:8.5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0433",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.9.0 allows remote attackers to affect confidentiality via vectors related to SSL support."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0434",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_applications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0436, CVE-2016-0437, and CVE-2016-0438."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-09T18:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0435",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_applications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality and integrity via vectors related to Mobile POS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-09T18:20Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0436",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_applications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0437, and CVE-2016-0438."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-09T18:21Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0437",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_applications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0436, and CVE-2016-0438."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-09T18:21Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0438",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_applications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0436, and CVE-2016-0437."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:13.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_applications:14.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-08T15:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0439",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect confidentiality via vectors related to SSL support, a different vulnerability than CVE-2016-0430."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0440",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to NFSv4."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Unsupported Solaris 11.x versions should be upgraded to a supported release or patch set. Refer to the Critical Patch Update January 2015 Patch Availability Document for Oracle Sun Systems Products Suite."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T23:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0441",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034712",
          "name" : "1034712",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Embedded Server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:3.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:C/I:C/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 9.5,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-06-08T15:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0442",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Loader Service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0443",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality via unknown vectors related to Agent Next Gen."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0444",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than CVE-2016-0447 and CVE-2016-0449."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0445",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0446",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality via unknown vectors related to Agent Next Gen."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0447",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than CVE-2016-0444 and CVE-2016-0449."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0448",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html",
          "name" : "SUSE-SU-2016:0256",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html",
          "name" : "openSUSE-SU-2016:0263",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html",
          "name" : "SUSE-SU-2016:0265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html",
          "name" : "openSUSE-SU-2016:0268",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html",
          "name" : "SUSE-SU-2016:0269",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html",
          "name" : "openSUSE-SU-2016:0270",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html",
          "name" : "openSUSE-SU-2016:0272",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html",
          "name" : "openSUSE-SU-2016:0279",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0049.html",
          "name" : "RHSA-2016:0049",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0050.html",
          "name" : "RHSA-2016:0050",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0053.html",
          "name" : "RHSA-2016:0053",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0054.html",
          "name" : "RHSA-2016:0054",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0055.html",
          "name" : "RHSA-2016:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0056.html",
          "name" : "RHSA-2016:0056",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0057.html",
          "name" : "RHSA-2016:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0067.html",
          "name" : "RHSA-2016:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3458",
          "name" : "DSA-3458",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3465",
          "name" : "DSA-3465",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81123",
          "name" : "81123",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034715",
          "name" : "1034715",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2884-1",
          "name" : "USN-2884-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2885-1",
          "name" : "USN-2885-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-14",
          "name" : "GLSA-201603-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related to JMX."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_66:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0449",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than CVE-2016-0444 and CVE-2016-0447."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2016-12-07T18:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0450",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "goldengate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81117",
          "name" : "81117",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-021",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-021",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://redr2e.com/cve-to-poc-cve-2016-0450/",
          "name" : "https://redr2e.com/cve-to-poc-cve-2016-0450/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:goldengate:11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:goldengate:12.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T02:59Z",
    "lastModifiedDate" : "2017-01-03T19:40Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0451",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "goldengate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81125",
          "name" : "81125",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-022",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-022",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://redr2e.com/cve-to-poc-cve-2016-0451/",
          "name" : "https://redr2e.com/cve-to-poc-cve-2016-0451/",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0452."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  The CVSS score is 10.0 only on Windows for Database versions prior to 12c. The CVSS is 7.5 (Confidentiality, Integrity and Availability is \"Partial+\") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:goldengate:11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:goldengate:12.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-01-03T19:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0452",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "goldengate",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81122",
          "name" : "81122",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-023",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-023",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0451."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  The CVSS score is 10.0 only on Windows for Database versions prior to 12c. The CVSS is 7.5 (Confidentiality, Integrity and Availability is \"Partial+\") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:goldengate:11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:goldengate:12.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T22:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0453",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034712",
          "name" : "1034712",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote attackers to affect integrity via unknown vectors related to Embedded Server."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:3.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.8
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.2,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T15:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0454",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Mobile Application Servlet component in Oracle E-Business Suite 12.1 and 12.2 allows local users to affect confidentiality via vectors related to MWA Server Manager."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0455",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality and availability via unknown vectors related to Agent Next Gen."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.1.0.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 7.8,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0456",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://erpscan.io/advisories/erpscan-16-006-oracle-e-business-suite-xxe-injection-vulnerability/",
          "name" : "https://erpscan.io/advisories/erpscan-16-006-oracle-e-business-suite-xxe-injection-vulnerability/",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0457. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/copxmllcmservicecontroller.js."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2018-12-10T19:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0457",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://erpscan.io/advisories/erpscan-16-007-oracle-e-business-suite-xxe-injection-vulnerability/",
          "name" : "https://erpscan.io/advisories/erpscan-16-007-oracle-e-business-suite-xxe-injection-vulnerability/",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0456.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/lcmServiceController.jsp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2018-12-10T19:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0458",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via vectors related to Kernel DAX."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T22:19Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0459",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote authenticated users to affect integrity via unknown vectors related to Popup Windows."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0460",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.55 allows remote attackers to affect integrity via unknown vectors related to Fluid Homepage and NavBar."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0461",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034709",
          "name" : "1034709",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T23:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0462",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect confidentiality via unknown vectors related to Multichannel Framework, a different vulnerability than CVE-2015-2650."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-08-30T17:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0463",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect confidentiality via unknown vectors related to Portal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T15:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0464",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81185",
          "name" : "81185",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034716",
          "name" : "1034716",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to WLS-Console."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:10.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:12.1.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:12.1.3.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0465",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_and_sun_systems_product_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4 allows local users to affect availability via unknown vectors related to Resource Group Manager."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_and_sun_systems_product_suite:3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_and_sun_systems_product_suite:4.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0466",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html",
          "name" : "SUSE-SU-2016:0256",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html",
          "name" : "openSUSE-SU-2016:0263",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html",
          "name" : "SUSE-SU-2016:0265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html",
          "name" : "openSUSE-SU-2016:0268",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html",
          "name" : "SUSE-SU-2016:0269",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html",
          "name" : "openSUSE-SU-2016:0270",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html",
          "name" : "openSUSE-SU-2016:0272",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html",
          "name" : "openSUSE-SU-2016:0279",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0049.html",
          "name" : "RHSA-2016:0049",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0050.html",
          "name" : "RHSA-2016:0050",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0053.html",
          "name" : "RHSA-2016:0053",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0054.html",
          "name" : "RHSA-2016:0054",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0055.html",
          "name" : "RHSA-2016:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0056.html",
          "name" : "RHSA-2016:0056",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0057.html",
          "name" : "RHSA-2016:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0067.html",
          "name" : "RHSA-2016:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3458",
          "name" : "DSA-3458",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3465",
          "name" : "DSA-3465",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81118",
          "name" : "81118",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034715",
          "name" : "1034715",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2884-1",
          "name" : "USN-2884-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2885-1",
          "name" : "USN-2885-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10148",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10148",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-14",
          "name" : "GLSA-201603-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect availability via vectors related to JAXP."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_66:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0467",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034709",
          "name" : "1034709",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect integrity via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0468",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035618",
          "name" : "1035618",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence:11.1.1.7.0:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence:11.1.1.9.0:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence:12.2.1.0.0:*:*:*:enterprise:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0469",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "micros_c2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.89.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035600",
          "name" : "1035600",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_c2:9.89.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:C/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0470",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "fusion_middleware",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to BI Publisher Security."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:11.1.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:fusion_middleware:12.2.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0471",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect confidentiality via unknown vectors related to Multichannel Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T15:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0472",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034709",
          "name" : "1034709",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality and availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0473",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T15:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0474",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T15:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0475",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jrockit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r28.3.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html",
          "name" : "SUSE-SU-2016:0256",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0049.html",
          "name" : "RHSA-2016:0049",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0050.html",
          "name" : "RHSA-2016:0050",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0055.html",
          "name" : "RHSA-2016:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034715",
          "name" : "1034715",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10148",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10148",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jrockit:r28.3.8:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0476",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81199",
          "name" : "81199",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-045",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-045",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0477 and CVE-2016-0478.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0477",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81153",
          "name" : "81153",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-041",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-041",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0476 and CVE-2016-0478.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the (1) repository, (2) workspace, or (3) scenario parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0478",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81163",
          "name" : "81163",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-036",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-036",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0476 and CVE-2016-0477.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0479",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035618",
          "name" : "1035618",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality and integrity via vectors related to Analytics Scorecard."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence:11.1.1.7.0:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence:11.1.1.9.0:*:*:*:enterprise:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence:12.2.1.0.0:*:*:*:enterprise:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0480",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81070",
          "name" : "81070",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-043",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-043",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0481, CVE-2016-0482, CVE-2016-0485, and CVE-2016-0486.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the TMAPReportImage parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0481",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_manager_grid_control",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81097",
          "name" : "81097",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-044",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-044",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0482, CVE-2016-0485, and CVE-2016-0486.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scheduleReportName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_grid_control:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0482",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81100",
          "name" : "81100",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-037",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-037",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0485, and CVE-2016-0486.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0483",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jrockit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r28.3.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html",
          "name" : "SUSE-SU-2016:0256",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html",
          "name" : "openSUSE-SU-2016:0263",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html",
          "name" : "SUSE-SU-2016:0265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html",
          "name" : "openSUSE-SU-2016:0268",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html",
          "name" : "SUSE-SU-2016:0269",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html",
          "name" : "openSUSE-SU-2016:0270",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html",
          "name" : "openSUSE-SU-2016:0272",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html",
          "name" : "openSUSE-SU-2016:0279",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0049.html",
          "name" : "RHSA-2016:0049",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0050.html",
          "name" : "RHSA-2016:0050",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0053.html",
          "name" : "RHSA-2016:0053",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0054.html",
          "name" : "RHSA-2016:0054",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0055.html",
          "name" : "RHSA-2016:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0056.html",
          "name" : "RHSA-2016:0056",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0057.html",
          "name" : "RHSA-2016:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0067.html",
          "name" : "RHSA-2016:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3458",
          "name" : "DSA-3458",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3465",
          "name" : "DSA-3465",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034715",
          "name" : "1034715",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2884-1",
          "name" : "USN-2884-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2885-1",
          "name" : "USN-2885-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-032",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-032",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-14",
          "name" : "GLSA-201603-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_66:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jrockit:r28.3.8:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0484",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81102",
          "name" : "81102",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-034",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-034",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0485",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81105",
          "name" : "81105",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-046",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-046",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0486.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:37Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0486",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81107",
          "name" : "81107",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-040",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-040",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0485.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the exportFileName parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:22Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0487",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81124",
          "name" : "81124",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-033",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-033",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0490.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the process method in the ActionServlet servlet, which allows remote attackers to bypass authentication via directory traversal sequences following an unspecified URI string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0488",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81104",
          "name" : "81104",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-035",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-035",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0492.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function in the admin pages, which allows remote attackers to bypass authentication and gain administrator access via directory traversal sequences following a URI entry that does not require authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0489",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81184",
          "name" : "81184",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-038",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-038",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Test Manager for Web Apps.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the ActionServlet servlet, which allows remote authenticated users to upload and execute arbitrary files via directory traversal sequences in the tempfilename parameter in a ReportImage action."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0490",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81173",
          "name" : "81173",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-039",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-039",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0487.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the UploadServlet servlet, which allows remote attackers to upload and execute arbitrary files via directory traversal sequences in a filename header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0491",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.html",
          "name" : "http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_upload",
          "name" : "http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_upload",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81169",
          "name" : "81169",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-047",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-047",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39691/",
          "name" : "39691",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39852/",
          "name" : "39852",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that the UploadFileAction servlet allows remote authenticated users to upload and execute arbitrary files via an * (asterisk) character in the fileType parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0492",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_testing_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.5.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.html",
          "name" : "http://packetstormsecurity.com/files/137175/Oracle-ATS-Arbitrary-File-Upload.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_upload",
          "name" : "http://www.rapid7.com/db/modules/exploit/multi/http/oracle_ats_file_upload",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81158",
          "name" : "81158",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034734",
          "name" : "1034734",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-16-042",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-16-042",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39691/",
          "name" : "39691",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39852/",
          "name" : "39852",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-22T14:39Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0493",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via unknown vectors related to Kernel Cryptography."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:N/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.3
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T19:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0494",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.html",
          "name" : "SUSE-SU-2016:0256",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.html",
          "name" : "openSUSE-SU-2016:0263",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.html",
          "name" : "SUSE-SU-2016:0265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.html",
          "name" : "openSUSE-SU-2016:0268",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.html",
          "name" : "SUSE-SU-2016:0269",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html",
          "name" : "openSUSE-SU-2016:0270",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.html",
          "name" : "openSUSE-SU-2016:0272",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.html",
          "name" : "openSUSE-SU-2016:0279",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0049.html",
          "name" : "RHSA-2016:0049",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0050.html",
          "name" : "RHSA-2016:0050",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0053.html",
          "name" : "RHSA-2016:0053",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0054.html",
          "name" : "RHSA-2016:0054",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0055.html",
          "name" : "RHSA-2016:0055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0056.html",
          "name" : "RHSA-2016:0056",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0057.html",
          "name" : "RHSA-2016:0057",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0067.html",
          "name" : "RHSA-2016:0067",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3458",
          "name" : "DSA-3458",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3465",
          "name" : "DSA-3465",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034715",
          "name" : "1034715",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2884-1",
          "name" : "USN-2884-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2885-1",
          "name" : "USN-2885-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-14",
          "name" : "GLSA-201603-14",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update66:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_105:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_91:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_66:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0495",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "vm_virtualbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.debian.org/security/2016/dsa-3454",
          "name" : "DSA-3454",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81214",
          "name" : "81214",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034731",
          "name" : "1034731",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and 5.0.14 allows remote attackers to affect availability via unknown vectors related to Core."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "4.0.0",
          "versionEndExcluding" : "4.3.36"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.0.0",
          "versionEndExcluding" : "5.0.14"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2019-02-14T19:12Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0496",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "micros_cwdirect",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "18.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the MICROS CWDirect component in Oracle Retail Applications 12.5, 13.0, 14.0, 15.0, 16.0, 17.0, and 18.0 allows remote attackers to affect confidentiality via unknown vectors related to Order Entry."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:12.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:14.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:15.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:16.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:17.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_cwdirect:18.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T17:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0497",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "agile_engineering_data_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034727",
          "name" : "1034727",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows remote attackers to affect integrity via unknown vectors related to Web Client."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:agile_engineering_data_management:6.1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:agile_engineering_data_management:6.1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T19:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0498",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "agile_engineering_data_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034727",
          "name" : "1034727",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:agile_engineering_data_management:6.1.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:agile_engineering_data_management:6.1.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 2.7,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T19:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0499",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034709",
          "name" : "1034709",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4794."
        }, {
          "lang" : "en",
          "value" : "Per Oracle:  The CVSS score is 9.0 only on Windows for Database versions prior to 12c. The CVSS is 6.5 (Confidentiality, Integrity and Availability is \"Partial+\") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-12-07T19:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0500",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_order_broker_cloud_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Order Broker Cloud Service component in Oracle Retail Applications 4.0 and 4.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to System Administration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_broker_cloud_service:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_broker_cloud_service:4.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T17:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0501",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "secure_global_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034729",
          "name" : "1034729",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.2 allows remote attackers to affect availability via vectors related to SGD Core."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:secure_global_desktop:5.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T17:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0502",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.31"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2019-02-14T19:09Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0503",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.27",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81126",
          "name" : "81126",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0504",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.27",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81077",
          "name" : "81077",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0503."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.7.9:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0505",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81088",
          "name" : "81088",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0506",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_order_management_system_cloud_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Order Management System Cloud Service component in Oracle Retail Applications 3.5, 4.5, 4.7, 5.0, and 15.0 allows remote attackers to affect confidentiality via unknown vectors related to Order Entry."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_management_system_cloud_service:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_management_system_cloud_service:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_management_system_cloud_service:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_management_system_cloud_service:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_management_system_cloud_service:15.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T17:36Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0507",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AR Web Utilities, a different vulnerability than CVE-2016-0519."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0508",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "ilearning",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034717",
          "name" : "1034717",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Administration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:ilearning:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:ilearning:6.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2016-06-08T17:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0509",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Internet Expenses component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AP Web Utilities."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0510",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Business Views Catalog."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0511",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0547, CVE-2016-0548, and CVE-2016-0549."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:00Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0512",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Self Service - Common Modules."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0513",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0514",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0515."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0515",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0514."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0516",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Quality component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to QA / Order Management Integration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0517",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to General utilities, a different vulnerability than CVE-2016-0518."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0518",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to General utilities, a different vulnerability than CVE-2016-0517."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0519",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AR Web Utilities, a different vulnerability than CVE-2016-0507."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0520",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_object_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to Java APIs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0521",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Redirection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0522",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "retail_open_commerce_platform_cloud_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034718",
          "name" : "1034718",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail Open Commerce Platform Cloud Service component in Oracle Retail Applications 3.5, 4.5, 4.7, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_open_commerce_platform_cloud_service:3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_open_commerce_platform_cloud_service:4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_open_commerce_platform_cloud_service:4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_open_commerce_platform_cloud_service:5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2016-06-08T17:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0523",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "interaction_blending",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Interaction Blending component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Blending Administration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_blending:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0524",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Work Provider Administration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0525",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "universal_work_queue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Work Provider Administration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:universal_work_queue:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:universal_work_queue:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:universal_work_queue:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:universal_work_queue:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0526",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via unknown vectors related to Wireless Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0527",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0528, CVE-2016-0529, and CVE-2016-0530."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0528",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0529, and CVE-2016-0530."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0529",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_interaction_history",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and CVE-2016-0530."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0530",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_interaction_history",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and CVE-2016-0529."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_interaction_history:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0531",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "applications_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Oracle Diagnostics Interfaces."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:applications_manager:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0532",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "crm_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security Assignments."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0533",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "crm_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Messaging."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0534",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "project_contracts",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Project Contracts component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Printing."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:project_contracts:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:project_contracts:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:project_contracts:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0535",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to RPC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0536",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "universal_work_queue",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to error messages."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:universal_work_queue:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0537",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "human_resources",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Person."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:human_resources:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0538",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "financial_consolidation_hub",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Financial Consolidation Hub component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Business Intelligence."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:financial_consolidation_hub:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:financial_consolidation_hub:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:financial_consolidation_hub:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:financial_consolidation_hub:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0539",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "report_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:report_manager:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:report_manager:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:report_manager:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:report_manager:12.2.4:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0540",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "configurator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034727",
          "name" : "1034727",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect confidentiality via unknown vectors related to UI Servlet, a different vulnerability than CVE-2016-0541."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:configurator:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:configurator:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:configurator:12.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0541",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "configurator",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034727",
          "name" : "1034727",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect confidentiality via unknown vectors related to UI Servlet, a different vulnerability than CVE-2016-0540."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:configurator:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:configurator:12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:configurator:12.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0542",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "field_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via unknown vectors related to Field Service Map."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:field_service:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:field_service:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:field_service:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:field_service:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:field_service:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:field_service:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0543",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Preview."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0544",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Architecture."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0545",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0551, CVE-2016-0552, CVE-2016-0559, and CVE-2016-0560."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0546",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81066",
          "name" : "81066",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1301493",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1301493",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-47.html",
          "name" : "https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-47.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-28.html",
          "name" : "https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-28.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://github.com/mysql/mysql-server/commit/0dbd5a8797ed4bd18e8b883988fb62177eb0f73f",
          "name" : "https://github.com/mysql/mysql-server/commit/0dbd5a8797ed4bd18e8b883988fb62177eb0f73f",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that these are multiple buffer overflows in the mysqlshow tool that allow remote database servers to have unspecified impact via a long table or database name."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0547",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0548, and CVE-2016-0549."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0548",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0549."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0549",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0548."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0550",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_relationship_management_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to CRM HTML Administration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0551",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0552, CVE-2016-0559, and CVE-2016-0560."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0552",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0551, CVE-2016-0559, and CVE-2016-0560."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0553",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0554",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "interaction_center_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Interaction Center Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Business Intelligence."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_center_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_center_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_center_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:interaction_center_intelligence:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0555",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "cadview-3d",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CADView-3D component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Studio."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:cadview-3d:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:cadview-3d:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:cadview-3d:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:cadview-3d:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0556",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0557."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0557",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "advanced_collections",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0556."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:advanced_collections:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:advanced_collections:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:advanced_collections:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:advanced_collections:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0558",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "service_contracts",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Service Contracts component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Renewals."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:service_contracts:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:service_contracts:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:service_contracts:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:service_contracts:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0559",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0551, CVE-2016-0552, and CVE-2016-0560."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0560",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0551, CVE-2016-0552, and CVE-2016-0559."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_intelligence:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0561",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0564."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0562",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "common_applications",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Common Applications component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via vectors related to CRM User Management Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:common_applications:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:common_applications:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:common_applications:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:common_applications:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0563",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "crm_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Techstack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0564",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0561."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0565",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0566",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "marketing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via unknown vectors related to Deliverables."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:marketing:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0567",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Embedded Data Warehouse."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0568",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "email_center",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Email Center component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Server Components."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:email_center:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:email_center:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:email_center:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0569",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_intelligence",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_intelligence:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0570",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "human_capital_management_configuration_workbench",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle HCM Configuration Workbench component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:human_capital_management_configuration_workbench:12.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:human_capital_management_configuration_workbench:12.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:human_capital_management_configuration_workbench:12.1.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0571",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "balanced_scorecard",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Balanced Scorecard component in Oracle E-Business Suite 11.5.10.2 and 12.1 allows remote attackers to affect confidentiality via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:balanced_scorecard:11.5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:balanced_scorecard:12.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:01Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0572",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034716",
          "name" : "1034716",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Coherence Container."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0573",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81085",
          "name" : "81085",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034716",
          "name" : "1034716",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Java Messaging Service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0574",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81080",
          "name" : "81080",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034716",
          "name" : "1034716",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0577."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0575",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "e-business_suite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Learning Management component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to OTA Self Service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0576",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_object_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to ICX LOVs."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0577",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81116",
          "name" : "81116",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034716",
          "name" : "1034716",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0574."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0578",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_relationship_management_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0579",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_relationship_management_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0582, CVE-2016-0583, and CVE-2016-0584."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0580",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "report_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:report_manager:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0581",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "approvals_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Approvals Management component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to AME Page rendering."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:approvals_management:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0582",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_relationship_management_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-2016-0583, and CVE-2016-0584."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0583",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "crm_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-2016-0582, and CVE-2016-0584."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:crm_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0584",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "customer_relationship_management_technical_foundation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-2016-0582, and CVE-2016-0583."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:customer_relationship_management_technical_foundation:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0585",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_object_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect availability via vectors related to ICX Error."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0586",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_object_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to iHelp."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0587",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors related to File Processing."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2016-06-08T17:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0588",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "general_ledger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle General Ledger component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Consolidation Hierarchy Viewer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:general_ledger:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0589",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_object_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.5.10.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034726",
          "name" : "1034726",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:11.5.10.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0590",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_supply_chain_management_order_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise SCM Order Management component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote attackers to affect integrity via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_order_management:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_order_management:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2016-06-08T17:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0591",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_supply_chain_management_purchasing",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034720",
          "name" : "1034720",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise SCM Purchasing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Supplier Change."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_purchasing:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_purchasing:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2016-06-09T18:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0592",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "vm_virtualbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.debian.org/security/2016/dsa-3454",
          "name" : "DSA-3454",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81224",
          "name" : "81224",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034731",
          "name" : "1034731",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and before 5.0.14 allows local users to affect availability via unknown vectors related to Core."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "4.0.0",
          "versionEndExcluding" : "4.3.36"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.0.0",
          "versionEndExcluding" : "5.0.14"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-02-19T18:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0593",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0594",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.21",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.21 and earlier allows remote authenticated users to affect availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.21"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0595",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.27",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81121",
          "name" : "81121",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.27"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0596",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81130",
          "name" : "81130",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0597",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81151",
          "name" : "81151",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0598",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81182",
          "name" : "81182",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0599",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0600",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81188",
          "name" : "81188",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0601",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Partition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.7.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2016-12-07T18:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0602",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "vm_virtualbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.12",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/fulldisclosure/2016/Feb/54",
          "name" : "20160210 [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537462/100/0/threaded",
          "name" : "20160205 [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034731",
          "name" : "1034731",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Windows Installer.  NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the \"application directory.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-09T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0603",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://seclists.org/fulldisclosure/2016/Feb/54",
          "name" : "20160210 [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox",
          "refsource" : "FULLDISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537462/100/0/threaded",
          "name" : "20160205 [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83008",
          "name" : "83008",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034969",
          "name" : "1034969",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160217-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160217-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.  NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the \"application directory.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_111:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_95:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_71:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_72:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_111:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_95:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update72:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.6
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 4.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-08T16:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0604",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0605",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81253",
          "name" : "81253",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.6.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0606",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0607",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.27",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81238",
          "name" : "81238",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.7.9:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:M/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.8
        },
        "severity" : "LOW",
        "exploitabilityScore" : 5.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0608",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81226",
          "name" : "81226",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0609",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81258",
          "name" : "81258",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.23"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:M/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.2,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0610",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.46",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.27",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81198",
          "name" : "81198",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10022-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10022-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-1019-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-1019-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.27"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.8:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0611",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.27",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.html",
          "name" : "openSUSE-SU-2016:0367",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00016.html",
          "name" : "openSUSE-SU-2016:0377",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81164",
          "name" : "81164",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.6.27"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:5.7.9:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-05-01T18:11Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0612",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0613",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0614",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "business_intelligence_publisher",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.1.1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.1.1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034711",
          "name" : "1034711",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence_publisher:11.1.1.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence_publisher:11.1.1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:business_intelligence_publisher:12.2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0615",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0616",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.46",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.46",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3453",
          "name" : "DSA-3453",
          "refsource" : "DEBIAN",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3459",
          "name" : "DSA-3459",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81176",
          "name" : "81176",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034708",
          "name" : "1034708",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2881-1",
          "name" : "USN-2881-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10110-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5547-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "name" : "https://mariadb.com/kb/en/mdb-10023-rn/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.5.46"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:10.1.9:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.5.46"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0617",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034968",
          "name" : "1034968",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:linux:6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-30T14:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0618",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034735",
          "name" : "1034735",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors related to Zones."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:M/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.4
        },
        "severity" : "LOW",
        "exploitabilityScore" : 2.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-21T03:02Z",
    "lastModifiedDate" : "2016-12-22T16:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0619",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0620",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0621",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0622",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0623",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035629",
          "name" : "1035629",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect integrity via vectors related to the Automated Installer sub-component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0624",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0625",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0626",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0627",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0628",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0629",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0630",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0631",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0632",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0633",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0634",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "gnu",
            "product" : {
              "product_data" : [ {
                "product_name" : "bash",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-78"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2017-0725.html",
          "name" : "RHSA-2017:0725",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/16/12",
          "name" : "[oss-security] 20160916 Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/16/8",
          "name" : "[oss-security] 20160916 CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/18/11",
          "name" : "[oss-security] 20160918 Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/19/7",
          "name" : "[oss-security] 20160919 Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/20/1",
          "name" : "[oss-security] 20160920 Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/27/9",
          "name" : "[oss-security] 20160927 Re: Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/09/29/27",
          "name" : "[oss-security] 20160929 Re: Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/10/07/6",
          "name" : "[oss-security] 20161007 Re: Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/10/10/3",
          "name" : "[oss-security] 20161010 RE: Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/10/10/4",
          "name" : "[oss-security] 20161010 Re: Re: CVE-2016-0634 -- bash prompt expanding $HOSTNAME",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92999",
          "name" : "92999",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1931",
          "name" : "RHSA-2017:1931",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1377613",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1377613",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Patch", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201612-39",
          "name" : "GLSA-201612-39",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The expansion of '\\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:gnu:bash:4.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-08-28T15:29Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0635",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "documaker",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.5",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "enterprise_manager_ops_center",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.3.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "health_sciences_information_manager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "healthcare_master_person_index",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "insurance_calculation_engine",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "insurance_policy_administration_j2ee",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "insurance_rules_palette",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.2.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "primavera_contract_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "14.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "primavera_p6_enterprise_project_portfolio_management",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "retail_integration_bus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "15.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "retail_order_broker_cloud_service",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91869",
          "name" : "91869",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036377",
          "name" : "1036377",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036378",
          "name" : "1036378",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036393",
          "name" : "1036393",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036397",
          "name" : "1036397",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037640",
          "name" : "1037640",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html",
          "name" : "https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html",
          "name" : "https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine component in Oracle Insurance Applications 9.7.1, 10.1.2, and 10.2.2; the Oracle Insurance Policy Administration J2EE and Oracle Insurance Rules Palette components in Oracle Insurance Applications 9.6.1, 9.7.1, 10.0.1, 10.1.2, 10.2.0, and 10.2.2; the Oracle Retail Integration Bus component in Oracle Retail Applications 15.0; the Oracle Retail Order Broker component in Oracle Retail Applications 5.1, 5.2, and 15.0; the Primavera Contract Management component in Oracle Primavera Products Suite 14.2; the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.2, 8.3, 8.4, 15.1, 15.2, and 16.1; the Oracle Financial Services Analytical Applications Infrastructure component in Oracle Financial Services Applications 8.0.0, 8.0.1, 8.0.2, and 8.0.3; the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce 3.1.1, 3.1.2, 11.0, 11.1, and 11.2; the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5; the Oracle Communications BRM - Elastic Charging Engine 11.2.0.0.0 and 11.3.0.0.0; the Oracle Enterprise Repository Enterprise Repository 12.1.3.0.0; the Oracle Financial Services Behavior Detection Platform 8.0.1 and 8.0.2; the Oracle Hyperion Essbase 12.2.1.1; the Oracle Tuxedo System and Applications Monitor (TSAM) 11.1.1.2.0, 11.1.1.2.1, 11.1.1.2.1, 12.1.1.1.0, 12.1.3.0.0, and 12.2.2.0.0; the Oracle Communications WebRTC Session Controller component of Oracle Communications Applications (subcomponent: Security (Spring)) 7.0, 7.1 and 7.2; the Oracle Endeca Information Discovery Integrator 3.2; the Converged Commerce component of Oracle Retail Applications 16.0.1; the Oracle Identity Manager 11.1.2.3.0; Oracle Enterprise Manager for MySQL Database 12.1.0.4; Oracle Retail Invoice Matching 12.0, 13.0, 13.1, 13.2, 14.0, and 14.1; Oracle Communications Performance Intelligence Center (PIC) Software Prior to 10.2.1 and the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: AnswerFlow (Spring Framework)) version 8.5.1.0 - 8.5.1.7 and 8.6.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:documaker:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "12.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:health_sciences_information_manager:1.2.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:health_sciences_information_manager:2.0.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:health_sciences_information_manager:3.0.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:healthcare_master_person_index:2.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:healthcare_master_person_index:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:healthcare_master_person_index:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_calculation_engine:9.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_calculation_engine:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_calculation_engine:10.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:9.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:9.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_rules_palette:9.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_rules_palette:9.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_rules_palette:10.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_rules_palette:10.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_rules_palette:10.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:insurance_rules_palette:10.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_contract_management:14.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:15.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:15.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:16.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_broker_cloud_service:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_broker_cloud_service:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:retail_order_broker_cloud_service:15.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-07-21T10:12Z",
    "lastModifiedDate" : "2019-04-23T19:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0636",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "icedtea7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.6",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00003.html",
          "name" : "SUSE-SU-2016:0956",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00004.html",
          "name" : "SUSE-SU-2016:0957",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00005.html",
          "name" : "SUSE-SU-2016:0959",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00007.html",
          "name" : "openSUSE-SU-2016:0971",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00008.html",
          "name" : "openSUSE-SU-2016:0983",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00013.html",
          "name" : "openSUSE-SU-2016:1004",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00014.html",
          "name" : "openSUSE-SU-2016:1005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00035.html",
          "name" : "openSUSE-SU-2016:1042",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0511.html",
          "name" : "RHSA-2016:0511",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0512.html",
          "name" : "RHSA-2016:0512",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0513.html",
          "name" : "RHSA-2016:0513",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0514.html",
          "name" : "RHSA-2016:0514",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0515.html",
          "name" : "RHSA-2016:0515",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0516.html",
          "name" : "RHSA-2016:0516",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3558",
          "name" : "DSA-3558",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0636-2949497.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0636-2949497.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/85376",
          "name" : "85376",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035401",
          "name" : "1035401",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2942-1",
          "name" : "USN-2942-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-18",
          "name" : "GLSA-201606-18",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201610-08",
          "name" : "GLSA-201610-08",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160328-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160328-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Hotspot sub-component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:icedtea7:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.6"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_97:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update73:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update74:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_97:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_73:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_74:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-03-24T18:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0637",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0638",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.1.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035615",
          "name" : "1035615",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://www.tenable.com/security/research/tra-2016-09",
          "name" : "https://www.tenable.com/security/research/tra-2016-09",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.2.1.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0639",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86418",
          "name" : "86418",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Pluggable Authentication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-02-19T19:33Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0640",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86427",
          "name" : "86427",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.12"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0641",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86470",
          "name" : "86470",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.8,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0642",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86445",
          "name" : "86445",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.5,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:M/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 5.5,
        "impactScore" : 4.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0643",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86486",
          "name" : "86486",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.49"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0644",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86442",
          "name" : "86442",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DDL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0645",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0646",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86436",
          "name" : "86436",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0647",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86495",
          "name" : "86495",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.49"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0648",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86457",
          "name" : "86457",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.49"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.14"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0649",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86498",
          "name" : "86498",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0650",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86496",
          "name" : "86496",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.47"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.12"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0651",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.46",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0534.html",
          "name" : "RHSA-2016:0534",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.5.46"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0652",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to DML."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0653",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to FTS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0654",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0656."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0655",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86424",
          "name" : "86424",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier and MariaDB 10.0.x before 10.0.25 and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to InnoDB."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.14"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0656",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0654."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0657",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect confidentiality via vectors related to JSON."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0658",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0659",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Optimizer."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0660",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0661",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86511",
          "name" : "86511",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0662",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Partition."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0663",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.10",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Performance Schema."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.10"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0664",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0665",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86513",
          "name" : "86513",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0666",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "ibm",
            "product" : {
              "product_data" : [ {
                "product_name" : "powerkvm",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.13",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html",
          "name" : "SUSE-SU-2016:1279",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1480.html",
          "name" : "RHSA-2016:1480",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1481.html",
          "name" : "RHSA-2016:1481",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1602.html",
          "name" : "RHSA-2016:1602",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3557",
          "name" : "DSA-3557",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86509",
          "name" : "86509",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "name" : "http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Security: Privileges."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.20",
          "versionEndExcluding" : "5.5.49"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.25"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndExcluding" : "10.1.14"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.5.0",
          "versionEndIncluding" : "5.5.48"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:ibm:powerkvm:3.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0667",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.7.11",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2954-1",
          "name" : "USN-2954-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Locking."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.7.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:M/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 2.8
        },
        "severity" : "LOW",
        "exploitabilityScore" : 5.5,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0668",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "mariadb",
            "product" : {
              "product_data" : [ {
                "product_name" : "mariadb",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.1.12",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html",
          "name" : "SUSE-SU-2016:1619",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html",
          "name" : "SUSE-SU-2016:1620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html",
          "name" : "openSUSE-SU-2016:1664",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html",
          "name" : "openSUSE-SU-2016:1686",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0705.html",
          "name" : "RHSA-2016:0705",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3595",
          "name" : "DSA-3595",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86467",
          "name" : "86467",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035606",
          "name" : "1035606",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2953-1",
          "name" : "USN-2953-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1132",
          "name" : "RHSA-2016:1132",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "name" : "https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.28"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.10"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.0.0",
          "versionEndExcluding" : "10.0.24"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.1.0",
          "versionEndIncluding" : "10.1.12"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.5,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:M/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "MULTIPLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 1.7
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.2,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0669",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035629",
          "name" : "1035629",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Fwflash."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.0,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.8,
        "impactScore" : 5.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:N/I:P/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 5.2
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.1,
        "impactScore" : 7.8,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0670",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-11T14:29Z",
    "lastModifiedDate" : "2017-05-11T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0671",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.2.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035617",
          "name" : "1035617",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:http_server:12.1.2.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0672",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "flexcube_direct_banking",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035604",
          "name" : "1035604",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:flexcube_direct_banking:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:flexcube_direct_banking:12.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0673",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "siebel_ui_framework",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035598",
          "name" : "1035598",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to UIF Open UI."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:siebel_ui_framework:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:siebel_ui_framework:8.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0674",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "siebel_core-common_components",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035598",
          "name" : "1035598",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality and integrity via vectors related to Email."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:siebel_core-common_components:8.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:siebel_core-common_components:8.2.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.2
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.1,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0675",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86450",
          "name" : "86450",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035615",
          "name" : "1035615",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0676",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035629",
          "name" : "1035629",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to the kernel."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.0,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:H/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 1.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0677",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035590",
          "name" : "1035590",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0678",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "vm_virtualbox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.18",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-05/msg00130.html",
          "name" : "openSUSE-SU-2016:1451",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-06/msg00002.html",
          "name" : "openSUSE-SU-2016:1462",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035607",
          "name" : "1035607",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.18 allows local users to affect confidentiality, integrity, and availability via vectors related to Core."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:vm_virtualbox:5.0.18:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:S/C:P/I:P/A:P",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.1
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 2.7,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0679",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "54",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect integrity and availability via vectors related to PIA Grids."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:54:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.7,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 5.8
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0680",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_supply_chain_management_eprocurement",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise SCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Services Procurement."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_eprocurement:9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_supply_chain_management_eprocurement:9.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0681",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "olap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035590",
          "name" : "1035590",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:olap:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:olap:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:olap:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0682",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_berkeley_db",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.5.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.1.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0689, CVE-2016-0692, CVE-2016-0694, and CVE-2016-3418."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.1.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.2.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.3.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-04-27T15:55Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0683",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Search Framework."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0684",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "micros_arspos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035600",
          "name" : "1035600",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Retail MICROS ARS POS component in Oracle Retail Applications 1.5 allows remote authenticated users to affect confidentiality via vectors related to POS."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:micros_arspos:1.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0685",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Processing."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0686",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html",
          "name" : "openSUSE-SU-2016:1222",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html",
          "name" : "openSUSE-SU-2016:1230",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html",
          "name" : "openSUSE-SU-2016:1235",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html",
          "name" : "SUSE-SU-2016:1248",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html",
          "name" : "SUSE-SU-2016:1250",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html",
          "name" : "openSUSE-SU-2016:1262",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html",
          "name" : "openSUSE-SU-2016:1265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html",
          "name" : "SUSE-SU-2016:1299",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html",
          "name" : "SUSE-SU-2016:1300",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html",
          "name" : "SUSE-SU-2016:1303",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html",
          "name" : "SUSE-SU-2016:1378",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html",
          "name" : "SUSE-SU-2016:1379",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html",
          "name" : "SUSE-SU-2016:1388",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html",
          "name" : "SUSE-SU-2016:1458",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html",
          "name" : "SUSE-SU-2016:1475",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0650.html",
          "name" : "RHSA-2016:0650",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0651.html",
          "name" : "RHSA-2016:0651",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0675.html",
          "name" : "RHSA-2016:0675",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0676.html",
          "name" : "RHSA-2016:0676",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0677.html",
          "name" : "RHSA-2016:0677",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0678.html",
          "name" : "RHSA-2016:0678",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0679.html",
          "name" : "RHSA-2016:0679",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html",
          "name" : "RHSA-2016:0701",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html",
          "name" : "RHSA-2016:0702",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html",
          "name" : "RHSA-2016:0708",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html",
          "name" : "RHSA-2016:0716",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0723.html",
          "name" : "RHSA-2016:0723",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html",
          "name" : "RHSA-2016:1039",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3558",
          "name" : "DSA-3558",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86473",
          "name" : "86473",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035596",
          "name" : "1035596",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2963-1",
          "name" : "USN-2963-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2964-1",
          "name" : "USN-2964-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2972-1",
          "name" : "USN-2972-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1216",
          "name" : "RHSA-2017:1216",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-18",
          "name" : "GLSA-201606-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160420-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160420-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Serialization."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_113:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_99:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_113:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_99:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_77:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.6,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 6.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0687",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html",
          "name" : "openSUSE-SU-2016:1222",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html",
          "name" : "openSUSE-SU-2016:1230",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html",
          "name" : "openSUSE-SU-2016:1235",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html",
          "name" : "SUSE-SU-2016:1248",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html",
          "name" : "SUSE-SU-2016:1250",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html",
          "name" : "openSUSE-SU-2016:1262",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html",
          "name" : "openSUSE-SU-2016:1265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html",
          "name" : "SUSE-SU-2016:1299",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html",
          "name" : "SUSE-SU-2016:1300",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html",
          "name" : "SUSE-SU-2016:1303",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html",
          "name" : "SUSE-SU-2016:1378",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html",
          "name" : "SUSE-SU-2016:1379",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html",
          "name" : "SUSE-SU-2016:1388",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html",
          "name" : "SUSE-SU-2016:1458",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html",
          "name" : "SUSE-SU-2016:1475",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0650.html",
          "name" : "RHSA-2016:0650",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0651.html",
          "name" : "RHSA-2016:0651",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0675.html",
          "name" : "RHSA-2016:0675",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0676.html",
          "name" : "RHSA-2016:0676",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0677.html",
          "name" : "RHSA-2016:0677",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0678.html",
          "name" : "RHSA-2016:0678",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0679.html",
          "name" : "RHSA-2016:0679",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html",
          "name" : "RHSA-2016:0701",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html",
          "name" : "RHSA-2016:0702",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html",
          "name" : "RHSA-2016:0708",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html",
          "name" : "RHSA-2016:0716",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0723.html",
          "name" : "RHSA-2016:0723",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html",
          "name" : "RHSA-2016:1039",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3558",
          "name" : "DSA-3558",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86459",
          "name" : "86459",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035596",
          "name" : "1035596",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2963-1",
          "name" : "USN-2963-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2964-1",
          "name" : "USN-2964-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2972-1",
          "name" : "USN-2972-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1430",
          "name" : "RHSA-2016:1430",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1216",
          "name" : "RHSA-2017:1216",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-18",
          "name" : "GLSA-201606-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160420-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160420-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the Hotspot sub-component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_113:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_99:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_113:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_99:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_77:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.6,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 6.0
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0688",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86469",
          "name" : "86469",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035615",
          "name" : "1035615",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to Core Components."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0689",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_berkeley_db",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.5.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.1.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0692, CVE-2016-0694, and CVE-2016-3418."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.1.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.2.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.3.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-04-27T18:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0690",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035590",
          "name" : "1035590",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0691."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0691",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "database",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035590",
          "name" : "1035590",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:11.2.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:12.1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:database:12.1.0.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0692",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_berkeley_db",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.5.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.1.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0689, CVE-2016-0694, and CVE-2016-3418."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.1.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.2.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.3.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-04-27T16:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0693",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035629",
          "name" : "1035629",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the PAM LDAP module."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0694",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "oracle_berkeley_db",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.2.5.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.1.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.2.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.2.5.3.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.6.1.26",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0689, CVE-2016-0692, and CVE-2016-3418."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.1.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.2.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:11.2.5.3.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:oracle_berkeley_db:12.1.6.1.26:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 6.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.4,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-04-27T17:54Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0695",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "jdk",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jre",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "jrockit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "r28.3.9",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "icedtea7",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.6",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.7.z",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.html",
          "name" : "openSUSE-SU-2016:1222",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.html",
          "name" : "openSUSE-SU-2016:1230",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.html",
          "name" : "openSUSE-SU-2016:1235",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.html",
          "name" : "SUSE-SU-2016:1248",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.html",
          "name" : "SUSE-SU-2016:1250",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.html",
          "name" : "openSUSE-SU-2016:1262",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.html",
          "name" : "openSUSE-SU-2016:1265",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0650.html",
          "name" : "RHSA-2016:0650",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0651.html",
          "name" : "RHSA-2016:0651",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0675.html",
          "name" : "RHSA-2016:0675",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0676.html",
          "name" : "RHSA-2016:0676",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0677.html",
          "name" : "RHSA-2016:0677",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0678.html",
          "name" : "RHSA-2016:0678",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0679.html",
          "name" : "RHSA-2016:0679",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0723.html",
          "name" : "RHSA-2016:0723",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3558",
          "name" : "DSA-3558",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86438",
          "name" : "86438",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035596",
          "name" : "1035596",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2963-1",
          "name" : "USN-2963-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2964-1",
          "name" : "USN-2964-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2972-1",
          "name" : "USN-2972-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10159",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10159",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-18",
          "name" : "GLSA-201606-18",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160420-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160420-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.6.0:update_113:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.7.0:update_99:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jdk:1.8.0:update77:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.6.0:update_113:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.7.0:update_99:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jre:1.8.0:update_77:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:jrockit:r28.3.9:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:icedtea7:*:rc1:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.6"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7.z:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2020-09-08T12:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0696",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86443",
          "name" : "86443",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035615",
          "name" : "1035615",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 allows remote attackers to affect confidentiality and integrity via vectors related to Console."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.5
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.4
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0697",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "application_object_library",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.2.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035603",
          "name" : "1035603",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows local users to affect confidentiality and integrity via unknown vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:12.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:12.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:12.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:application_object_library:12.2.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.0,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 0.8,
        "impactScore" : 5.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0698",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "peoplesoft_enterprise_peopletools",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.55",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035610",
          "name" : "1035610",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Rich Text Editor, a different vulnerability than CVE-2016-3423."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0699",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "flexcube_direct_banking",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035604",
          "name" : "1035604",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:flexcube_direct_banking:12.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:flexcube_direct_banking:12.0.3:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 9.1,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "NONE",
          "baseScore" : 9.4
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 9.2,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0700",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "weblogic_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.3.6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.1.3.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-noinfo"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/86453",
          "name" : "86453",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035615",
          "name" : "1035615",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-21T10:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0701",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://intothesymmetry.blogspot.com/2016/01/openssl-key-recovery-attack-on-dh-small.html",
          "name" : "http://intothesymmetry.blogspot.com/2016/01/openssl-key-recovery-attack-on-dh-small.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176373.html",
          "name" : "FEDORA-2016-527018d2ff",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.openssl.org/news/secadv/20160128.txt",
          "name" : "http://www.openssl.org/news/secadv/20160128.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82233",
          "name" : "82233",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034849",
          "name" : "1034849",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2883-1",
          "name" : "USN-2883-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=878e2c5b13010329c203f309ed0c8f2113f85648",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=878e2c5b13010329c203f309ed0c8f2113f85648",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=c5b831f21d0d29d1e517d139d9d101763f60c9a2",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=c5b831f21d0d29d1e517d139d9d101763f60c9a2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03724en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03724en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05164821",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05164821",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390893",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390893",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201601-05",
          "name" : "GLSA-201601-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.kb.cert.org/vuls/id/257823",
          "name" : "VU#257823",
          "refsource" : "CERT-VN",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/security-alerts/cpuapr2020.html",
          "name" : "N/A",
          "refsource" : "N/A",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/security-alerts/cpujan2020.html",
          "name" : "https://www.oracle.com/security-alerts/cpujan2020.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/security-alerts/cpujul2020.html",
          "name" : "https://www.oracle.com/security-alerts/cpujul2020.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html",
          "name" : "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.7,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-15T02:59Z",
    "lastModifiedDate" : "2020-07-15T03:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0702",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://cachebleed.info",
          "name" : "http://cachebleed.info",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178358.html",
          "name" : "FEDORA-2016-2802690366",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178817.html",
          "name" : "FEDORA-2016-e6807b3394",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html",
          "name" : "openSUSE-SU-2016:0627",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html",
          "name" : "SUSE-SU-2016:0641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html",
          "name" : "openSUSE-SU-2016:0720",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html",
          "name" : "openSUSE-SU-2016:1239",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html",
          "name" : "openSUSE-SU-2016:1241",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html",
          "name" : "openSUSE-SU-2016:1242",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html",
          "name" : "SUSE-SU-2016:1267",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html",
          "name" : "openSUSE-SU-2016:1273",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html",
          "name" : "SUSE-SU-2016:1290",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html",
          "name" : "SUSE-SU-2016:1360",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html",
          "name" : "openSUSE-SU-2016:1566",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145889460330120&w=2",
          "name" : "HPSBGN03563",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2957.html",
          "name" : "RHSA-2016:2957",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3500",
          "name" : "DSA-3500",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2914-1",
          "name" : "USN-2914-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=708dc2f1291e104fe4eef810bb8ffc1fae5b19c1",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=708dc2f1291e104fe4eef810bb8ffc1fae5b19c1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a \"CacheBleed\" attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.4,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 1.9
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.4,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-03T20:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0703",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.8ze",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html",
          "name" : "SUSE-SU-2016:0641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html",
          "name" : "SUSE-SU-2016:0678",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html",
          "name" : "openSUSE-SU-2016:0720",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83743",
          "name" : "83743",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://drownattack.com",
          "name" : "https://drownattack.com",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=ae50d8270026edf5b3c7f8aaa0c6677462b33d97",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=ae50d8270026edf5b3c7f8aaa0c6677462b33d97",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.8ze"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-03-02T11:59Z",
    "lastModifiedDate" : "2018-01-18T18:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0704",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.8ze",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html",
          "name" : "SUSE-SU-2016:0641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html",
          "name" : "SUSE-SU-2016:0678",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html",
          "name" : "openSUSE-SU-2016:0720",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83764",
          "name" : "83764",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://drownattack.com",
          "name" : "https://drownattack.com",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=ae50d8270026edf5b3c7f8aaa0c6677462b33d97",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=ae50d8270026edf5b3c7f8aaa0c6677462b33d97",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a overwrites incorrect MASTER-KEY bytes during use of export cipher suites, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.8ze"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.0q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-02T11:59Z",
    "lastModifiedDate" : "2018-01-18T18:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0705",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "mysql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178358.html",
          "name" : "FEDORA-2016-2802690366",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178817.html",
          "name" : "FEDORA-2016-e6807b3394",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html",
          "name" : "openSUSE-SU-2016:0627",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html",
          "name" : "openSUSE-SU-2016:1332",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html",
          "name" : "openSUSE-SU-2016:1566",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145889460330120&w=2",
          "name" : "HPSBGN03563",
          "refsource" : "HP",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145983526810210&w=2",
          "name" : "HPSBGN03569",
          "refsource" : "HP",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=146108058503441&w=2",
          "name" : "HPSBMU03575",
          "refsource" : "HP",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2957.html",
          "name" : "RHSA-2016:2957",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-05-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-05-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3500",
          "name" : "DSA-3500",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83754",
          "name" : "83754",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2914-1",
          "name" : "USN-2914-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2018:2568",
          "name" : "RHSA-2018:2568",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2018:2575",
          "name" : "RHSA-2018:2575",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2018:2713",
          "name" : "RHSA-2018:2713",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=6c88c71b4e4825c7bc0489306d062d017634eb88",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=6c88c71b4e4825c7bc0489306d062d017634eb88",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05126404",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05126404",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05135617",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05135617",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150736",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150736",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05176716",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05176716",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/415.html\" rel=\"nofollow\">CWE-415: Double Free</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.6.0",
          "versionEndIncluding" : "5.6.29"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "5.7.0",
          "versionEndIncluding" : "5.7.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-03-03T20:59Z",
    "lastModifiedDate" : "2019-02-20T16:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0706",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html",
          "name" : "SUSE-SU-2016:0769",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html",
          "name" : "SUSE-SU-2016:0822",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00082.html",
          "name" : "SUSE-SU-2016:0839",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html",
          "name" : "openSUSE-SU-2016:0865",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145974991225029&w=2",
          "name" : "HPSBUX03561",
          "refsource" : "HP",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1089.html",
          "name" : "RHSA-2016:1089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2045.html",
          "name" : "RHSA-2016:2045",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2599.html",
          "name" : "RHSA-2016:2599",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2807.html",
          "name" : "RHSA-2016:2807",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2808.html",
          "name" : "RHSA-2016:2808",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/bugtraq/2016/Feb/144",
          "name" : "20160222 [SECURITY] CVE-2016-0706 Apache Tomcat Security Manager bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Mailing List" ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1722799",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1722799",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking" ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1722800",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1722800",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1722801",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1722801",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking" ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1722802",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1722802",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking" ]
        }, {
          "url" : "http://tomcat.apache.org/security-6.html",
          "name" : "http://tomcat.apache.org/security-6.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-7.html",
          "name" : "http://tomcat.apache.org/security-7.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-8.html",
          "name" : "http://tomcat.apache.org/security-8.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-9.html",
          "name" : "http://tomcat.apache.org/security-9.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3530",
          "name" : "DSA-3530",
          "refsource" : "DEBIAN",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3552",
          "name" : "DSA-3552",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3609",
          "name" : "DSA-3609",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83324",
          "name" : "83324",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035069",
          "name" : "1035069",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-3024-1",
          "name" : "USN-3024-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1087",
          "name" : "RHSA-2016:1087",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1088",
          "name" : "RHSA-2016:1088",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa118",
          "name" : "https://bto.bluecoat.com/security-advisory/sa118",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05054964",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05054964",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190413 svn commit: r1857494 [15/20] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [21/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190415 svn commit: r1857582 [16/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [23/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200203 svn commit: r1873527 [23/30] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [26/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [27/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201705-09",
          "name" : "GLSA-201705-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20180531-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20180531-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.1:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.4:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.5:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-25T01:59Z",
    "lastModifiedDate" : "2019-04-15T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0707",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "ambari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.1.2",
          "name" : "https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.1.2",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.3,
          "baseSeverity" : "LOW"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-18T14:59Z",
    "lastModifiedDate" : "2016-05-18T21:46Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0708",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cloudfoundry",
            "product" : {
              "product_data" : [ {
                "product_name" : "cf-release",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "166",
                    "version_affected" : "="
                  }, {
                    "version_value" : "167",
                    "version_affected" : "="
                  }, {
                    "version_value" : "168",
                    "version_affected" : "="
                  }, {
                    "version_value" : "169",
                    "version_affected" : "="
                  }, {
                    "version_value" : "170",
                    "version_affected" : "="
                  }, {
                    "version_value" : "171",
                    "version_affected" : "="
                  }, {
                    "version_value" : "172",
                    "version_affected" : "="
                  }, {
                    "version_value" : "173",
                    "version_affected" : "="
                  }, {
                    "version_value" : "174",
                    "version_affected" : "="
                  }, {
                    "version_value" : "175",
                    "version_affected" : "="
                  }, {
                    "version_value" : "176",
                    "version_affected" : "="
                  }, {
                    "version_value" : "177",
                    "version_affected" : "="
                  }, {
                    "version_value" : "178",
                    "version_affected" : "="
                  }, {
                    "version_value" : "179",
                    "version_affected" : "="
                  }, {
                    "version_value" : "180",
                    "version_affected" : "="
                  }, {
                    "version_value" : "181",
                    "version_affected" : "="
                  }, {
                    "version_value" : "182",
                    "version_affected" : "="
                  }, {
                    "version_value" : "183",
                    "version_affected" : "="
                  }, {
                    "version_value" : "184",
                    "version_affected" : "="
                  }, {
                    "version_value" : "185",
                    "version_affected" : "="
                  }, {
                    "version_value" : "186",
                    "version_affected" : "="
                  }, {
                    "version_value" : "187",
                    "version_affected" : "="
                  }, {
                    "version_value" : "188",
                    "version_affected" : "="
                  }, {
                    "version_value" : "189",
                    "version_affected" : "="
                  }, {
                    "version_value" : "190",
                    "version_affected" : "="
                  }, {
                    "version_value" : "191",
                    "version_affected" : "="
                  }, {
                    "version_value" : "192",
                    "version_affected" : "="
                  }, {
                    "version_value" : "193",
                    "version_affected" : "="
                  }, {
                    "version_value" : "194",
                    "version_affected" : "="
                  }, {
                    "version_value" : "195",
                    "version_affected" : "="
                  }, {
                    "version_value" : "196",
                    "version_affected" : "="
                  }, {
                    "version_value" : "197",
                    "version_affected" : "="
                  }, {
                    "version_value" : "198",
                    "version_affected" : "="
                  }, {
                    "version_value" : "199",
                    "version_affected" : "="
                  }, {
                    "version_value" : "200",
                    "version_affected" : "="
                  }, {
                    "version_value" : "201",
                    "version_affected" : "="
                  }, {
                    "version_value" : "202",
                    "version_affected" : "="
                  }, {
                    "version_value" : "203",
                    "version_affected" : "="
                  }, {
                    "version_value" : "204",
                    "version_affected" : "="
                  }, {
                    "version_value" : "205",
                    "version_affected" : "="
                  }, {
                    "version_value" : "206",
                    "version_affected" : "="
                  }, {
                    "version_value" : "207",
                    "version_affected" : "="
                  }, {
                    "version_value" : "208",
                    "version_affected" : "="
                  }, {
                    "version_value" : "209",
                    "version_affected" : "="
                  }, {
                    "version_value" : "210",
                    "version_affected" : "="
                  }, {
                    "version_value" : "211",
                    "version_affected" : "="
                  }, {
                    "version_value" : "212",
                    "version_affected" : "="
                  }, {
                    "version_value" : "213",
                    "version_affected" : "="
                  }, {
                    "version_value" : "214",
                    "version_affected" : "="
                  }, {
                    "version_value" : "215",
                    "version_affected" : "="
                  }, {
                    "version_value" : "216",
                    "version_affected" : "="
                  }, {
                    "version_value" : "217",
                    "version_affected" : "="
                  }, {
                    "version_value" : "218",
                    "version_affected" : "="
                  }, {
                    "version_value" : "219",
                    "version_affected" : "="
                  }, {
                    "version_value" : "220",
                    "version_affected" : "="
                  }, {
                    "version_value" : "221",
                    "version_affected" : "="
                  }, {
                    "version_value" : "222",
                    "version_affected" : "="
                  }, {
                    "version_value" : "223",
                    "version_affected" : "="
                  }, {
                    "version_value" : "224",
                    "version_affected" : "="
                  }, {
                    "version_value" : "225",
                    "version_affected" : "="
                  }, {
                    "version_value" : "226",
                    "version_affected" : "="
                  }, {
                    "version_value" : "227",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "java_buildpack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://www.cloudfoundry.org/blog/cve-2016-0708/",
          "name" : "https://www.cloudfoundry.org/blog/cve-2016-0708/",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack versions for some basic web application archive (WAR) packaged applications are vulnerable to this issue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "166",
          "versionEndIncluding" : "227"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:java_buildpack:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0",
          "versionEndIncluding" : "3.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-07-11T20:29Z",
    "lastModifiedDate" : "2018-09-11T18:49Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0709",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetspeed",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and",
          "name" : "http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/136489/Apache-Jetspeed-Arbitrary-File-Upload.html",
          "name" : "http://packetstormsecurity.com/files/136489/Apache-Jetspeed-Arbitrary-File-Upload.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.rapid7.com/db/modules/exploit/multi/http/apache_jetspeed_file_upload",
          "name" : "http://www.rapid7.com/db/modules/exploit/multi/http/apache_jetspeed_file_upload",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C281D02D0-6A03-4421-9D86-E73B001C8677@bluesunrise.com%3E",
          "name" : "[portals-jetspeed-user] 20160303 [CVE-2016-0709] Apache Jetspeed information disclosure vulnerability",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0709",
          "name" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0709",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39643/",
          "name" : "39643",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by \"../../webapps/x.jsp.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:jetspeed:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.2,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-11T14:59Z",
    "lastModifiedDate" : "2016-04-20T18:14Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0710",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetspeed",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and",
          "name" : "http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/136489/Apache-Jetspeed-Arbitrary-File-Upload.html",
          "name" : "http://packetstormsecurity.com/files/136489/Apache-Jetspeed-Arbitrary-File-Upload.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "http://www.rapid7.com/db/modules/exploit/multi/http/apache_jetspeed_file_upload",
          "name" : "http://www.rapid7.com/db/modules/exploit/multi/http/apache_jetspeed_file_upload",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C046318A1-226E-453F-9394-B84F1A33E6A4@bluesunrise.com%3E",
          "name" : "[portals-jetspeed-user] 20160303 [CVE-2016-0710] Apache Jetspeed information disclosure vulnerability",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0710",
          "name" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0710",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39643/",
          "name" : "39643",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ "Exploit" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:jetspeed:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-11T14:59Z",
    "lastModifiedDate" : "2016-04-20T18:24Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0711",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetspeed",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C73AC0763-D44B-4BDF-867C-05AD4674A62F@bluesunrise.com%3E",
          "name" : "[portals-jetspeed-user] 20160303 [CVE-2016-0711] Apache Jetspeed information disclosure vulnerability",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0711",
          "name" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0711",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:jetspeed:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-11T14:59Z",
    "lastModifiedDate" : "2016-04-20T18:41Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0712",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "jetspeed",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3CF868DBFC-A05C-4ABB-8B91-17CA54C174B9@bluesunrise.com%3E",
          "name" : "[portals-jetspeed-user] 20160303 [CVE-2016-0712] Apache Jetspeed information disclosure vulnerability",
          "refsource" : "MLIST",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0712",
          "name" : "https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0712",
          "refsource" : "CONFIRM",
          "tags" : [ "Exploit", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:jetspeed:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-11T14:59Z",
    "lastModifiedDate" : "2016-04-20T18:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0713",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "cloudfoundry",
            "product" : {
              "product_data" : [ {
                "product_name" : "cf-release",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "141",
                    "version_affected" : "="
                  }, {
                    "version_value" : "142",
                    "version_affected" : "="
                  }, {
                    "version_value" : "143",
                    "version_affected" : "="
                  }, {
                    "version_value" : "144",
                    "version_affected" : "="
                  }, {
                    "version_value" : "145",
                    "version_affected" : "="
                  }, {
                    "version_value" : "146",
                    "version_affected" : "="
                  }, {
                    "version_value" : "147",
                    "version_affected" : "="
                  }, {
                    "version_value" : "148",
                    "version_affected" : "="
                  }, {
                    "version_value" : "149",
                    "version_affected" : "="
                  }, {
                    "version_value" : "150",
                    "version_affected" : "="
                  }, {
                    "version_value" : "151",
                    "version_affected" : "="
                  }, {
                    "version_value" : "152",
                    "version_affected" : "="
                  }, {
                    "version_value" : "153",
                    "version_affected" : "="
                  }, {
                    "version_value" : "154",
                    "version_affected" : "="
                  }, {
                    "version_value" : "155",
                    "version_affected" : "="
                  }, {
                    "version_value" : "156",
                    "version_affected" : "="
                  }, {
                    "version_value" : "157",
                    "version_affected" : "="
                  }, {
                    "version_value" : "158",
                    "version_affected" : "="
                  }, {
                    "version_value" : "159",
                    "version_affected" : "="
                  }, {
                    "version_value" : "160",
                    "version_affected" : "="
                  }, {
                    "version_value" : "161",
                    "version_affected" : "="
                  }, {
                    "version_value" : "162",
                    "version_affected" : "="
                  }, {
                    "version_value" : "163",
                    "version_affected" : "="
                  }, {
                    "version_value" : "164",
                    "version_affected" : "="
                  }, {
                    "version_value" : "165",
                    "version_affected" : "="
                  }, {
                    "version_value" : "166",
                    "version_affected" : "="
                  }, {
                    "version_value" : "167",
                    "version_affected" : "="
                  }, {
                    "version_value" : "168",
                    "version_affected" : "="
                  }, {
                    "version_value" : "169",
                    "version_affected" : "="
                  }, {
                    "version_value" : "170",
                    "version_affected" : "="
                  }, {
                    "version_value" : "171",
                    "version_affected" : "="
                  }, {
                    "version_value" : "172",
                    "version_affected" : "="
                  }, {
                    "version_value" : "173",
                    "version_affected" : "="
                  }, {
                    "version_value" : "174",
                    "version_affected" : "="
                  }, {
                    "version_value" : "175",
                    "version_affected" : "="
                  }, {
                    "version_value" : "176",
                    "version_affected" : "="
                  }, {
                    "version_value" : "177",
                    "version_affected" : "="
                  }, {
                    "version_value" : "178",
                    "version_affected" : "="
                  }, {
                    "version_value" : "179",
                    "version_affected" : "="
                  }, {
                    "version_value" : "180",
                    "version_affected" : "="
                  }, {
                    "version_value" : "181",
                    "version_affected" : "="
                  }, {
                    "version_value" : "182",
                    "version_affected" : "="
                  }, {
                    "version_value" : "183",
                    "version_affected" : "="
                  }, {
                    "version_value" : "184",
                    "version_affected" : "="
                  }, {
                    "version_value" : "185",
                    "version_affected" : "="
                  }, {
                    "version_value" : "186",
                    "version_affected" : "="
                  }, {
                    "version_value" : "187",
                    "version_affected" : "="
                  }, {
                    "version_value" : "188",
                    "version_affected" : "="
                  }, {
                    "version_value" : "189",
                    "version_affected" : "="
                  }, {
                    "version_value" : "190",
                    "version_affected" : "="
                  }, {
                    "version_value" : "191",
                    "version_affected" : "="
                  }, {
                    "version_value" : "192",
                    "version_affected" : "="
                  }, {
                    "version_value" : "193",
                    "version_affected" : "="
                  }, {
                    "version_value" : "194",
                    "version_affected" : "="
                  }, {
                    "version_value" : "195",
                    "version_affected" : "="
                  }, {
                    "version_value" : "196",
                    "version_affected" : "="
                  }, {
                    "version_value" : "197",
                    "version_affected" : "="
                  }, {
                    "version_value" : "198",
                    "version_affected" : "="
                  }, {
                    "version_value" : "199",
                    "version_affected" : "="
                  }, {
                    "version_value" : "200",
                    "version_affected" : "="
                  }, {
                    "version_value" : "201",
                    "version_affected" : "="
                  }, {
                    "version_value" : "202",
                    "version_affected" : "="
                  }, {
                    "version_value" : "203",
                    "version_affected" : "="
                  }, {
                    "version_value" : "204",
                    "version_affected" : "="
                  }, {
                    "version_value" : "205",
                    "version_affected" : "="
                  }, {
                    "version_value" : "206",
                    "version_affected" : "="
                  }, {
                    "version_value" : "207",
                    "version_affected" : "="
                  }, {
                    "version_value" : "208",
                    "version_affected" : "="
                  }, {
                    "version_value" : "209",
                    "version_affected" : "="
                  }, {
                    "version_value" : "210",
                    "version_affected" : "="
                  }, {
                    "version_value" : "211",
                    "version_affected" : "="
                  }, {
                    "version_value" : "212",
                    "version_affected" : "="
                  }, {
                    "version_value" : "213",
                    "version_affected" : "="
                  }, {
                    "version_value" : "214",
                    "version_affected" : "="
                  }, {
                    "version_value" : "215",
                    "version_affected" : "="
                  }, {
                    "version_value" : "216",
                    "version_affected" : "="
                  }, {
                    "version_value" : "217",
                    "version_affected" : "="
                  }, {
                    "version_value" : "218",
                    "version_affected" : "="
                  }, {
                    "version_value" : "219",
                    "version_affected" : "="
                  }, {
                    "version_value" : "220",
                    "version_affected" : "="
                  }, {
                    "version_value" : "221",
                    "version_affected" : "="
                  }, {
                    "version_value" : "222",
                    "version_affected" : "="
                  }, {
                    "version_value" : "223",
                    "version_affected" : "="
                  }, {
                    "version_value" : "224",
                    "version_affected" : "="
                  }, {
                    "version_value" : "225",
                    "version_affected" : "="
                  }, {
                    "version_value" : "226",
                    "version_affected" : "="
                  }, {
                    "version_value" : "227",
                    "version_affected" : "="
                  }, {
                    "version_value" : "228",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://bosh.io/releases/github.com/cloudfoundry/cf-release?version=229",
          "name" : "https://bosh.io/releases/github.com/cloudfoundry/cf-release?version=229",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes", "Third Party Advisory" ]
        }, {
          "url" : "https://lists.cloudfoundry.org/archives/list/cf-dev@lists.cloudfoundry.org/thread/VWDLUNTDKW5CW5JWEM5BOHLJ3J32TAFF/",
          "name" : "[cf-dev] 20160201 CVE-2016-0713 Gorouter XSS",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:141:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:142:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:143:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:144:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:145:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:146:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:147:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:148:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:149:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:150:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:151:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:152:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:153:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:154:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:155:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:156:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:157:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:158:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:159:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:160:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:161:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:162:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:163:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:164:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:165:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:166:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:167:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:168:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:169:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:170:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:171:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:172:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:173:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:174:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:175:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:176:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:177:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:178:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:179:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:180:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:181:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:182:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:183:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:184:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:185:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:186:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:187:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:188:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:189:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:190:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:191:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:192:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:193:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:194:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:195:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:196:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:197:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:198:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:199:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:200:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:201:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:202:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:203:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:204:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:205:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:206:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:207:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:208:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:209:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:210:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:211:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:212:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:213:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:214:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:215:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:216:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:217:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:218:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:219:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:220:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:221:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:222:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:223:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:224:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:225:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:226:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:227:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:cloudfoundry:cf-release:228:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.7,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.6
        },
        "severity" : "LOW",
        "exploitabilityScore" : 4.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-08-31T14:29Z",
    "lastModifiedDate" : "2017-09-05T18:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0714",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html",
          "name" : "SUSE-SU-2016:0769",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html",
          "name" : "SUSE-SU-2016:0822",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00082.html",
          "name" : "SUSE-SU-2016:0839",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html",
          "name" : "openSUSE-SU-2016:0865",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145974991225029&w=2",
          "name" : "HPSBUX03561",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1089.html",
          "name" : "RHSA-2016:1089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2045.html",
          "name" : "RHSA-2016:2045",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2599.html",
          "name" : "RHSA-2016:2599",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2807.html",
          "name" : "RHSA-2016:2807",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2808.html",
          "name" : "RHSA-2016:2808",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/bugtraq/2016/Feb/145",
          "name" : "20160222 [SECURITY] CVE-2016-0714 Apache Tomcat Security Manager Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1725263",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1725263",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1725914",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1725914",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1726196",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1726196",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1726203",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1726203",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1726923",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1726923",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1727034",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1727034",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1727166",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1727166",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1727182",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1727182",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://tomcat.apache.org/security-6.html",
          "name" : "http://tomcat.apache.org/security-6.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-7.html",
          "name" : "http://tomcat.apache.org/security-7.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-8.html",
          "name" : "http://tomcat.apache.org/security-8.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-9.html",
          "name" : "http://tomcat.apache.org/security-9.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3530",
          "name" : "DSA-3530",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3552",
          "name" : "DSA-3552",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3609",
          "name" : "DSA-3609",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83327",
          "name" : "83327",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035069",
          "name" : "1035069",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037640",
          "name" : "1037640",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-3024-1",
          "name" : "USN-3024-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1087",
          "name" : "RHSA-2016:1087",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1088",
          "name" : "RHSA-2016:1088",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa118",
          "name" : "https://bto.bluecoat.com/security-advisory/sa118",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05054964",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05054964",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190413 svn commit: r1857494 [15/20] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [21/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190415 svn commit: r1857582 [16/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [23/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200203 svn commit: r1873527 [23/30] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [26/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [27/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201705-09",
          "name" : "GLSA-201705-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20180531-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20180531-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.0:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.1:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.4:alpha:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.5:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-25T01:59Z",
    "lastModifiedDate" : "2019-04-15T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0715",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pivotal_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_foundry_elastic_runtime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://pivotal.io/security/cve-2016-0715",
          "name" : "https://pivotal.io/security/cve-2016-0715",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigation configuration instructions provided as part of CVE-2016-0708 were incomplete and could leave PHP Buildpack, Staticfile Buildpack and potentially other custom Buildpack applications vulnerable to remote information disclosure. Affected applications use automated buildpack detection, serve files directly from the root of the application and have a buildpack that matched after the Java Buildpack in the system buildpack priority when Java Buildpack versions 2.0 through 3.4 were present."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.4.0",
          "versionEndIncluding" : "1.4.5"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.5.0",
          "versionEndIncluding" : "1.5.11"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "1.6.0",
          "versionEndIncluding" : "1.6.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-09-11T17:29Z",
    "lastModifiedDate" : "2019-10-09T23:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0716",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0729. Reason: This candidate is a reservation duplicate of CVE-2016-0729. Notes: All CVE users should reference CVE-2016-0729 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2016-02-18T15:59Z",
    "lastModifiedDate" : "2016-02-18T15:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0717",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0729. Reason: This candidate is a reservation duplicate of CVE-2016-0729. Notes: All CVE users should reference CVE-2016-0729 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2016-02-18T15:59Z",
    "lastModifiedDate" : "2016-02-18T15:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0718",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libexpat",
            "product" : {
              "product_data" : [ {
                "product_name" : "expat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.95.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "mozilla",
            "product" : {
              "product_data" : [ {
                "product_name" : "firefox",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "17.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "18.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "18.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "18.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "18.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "18.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "19.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "19.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "19.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "19.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "20.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "20.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "21.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "22.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "25.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "25.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "25.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "26.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "27.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "27.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "28.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "29.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "29.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "30.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "31.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "32.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "32.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "32.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "32.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "33.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "33.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "33.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "33.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "33.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "33.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "34.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "34.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "35.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "35.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "36.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "36.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "36.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "36.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "37.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "37.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "37.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "38.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "39.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "39.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "40.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "40.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "40.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "41.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "41.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "41.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "42.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "43.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "43.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "43.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "43.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "43.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "44.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "44.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "44.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "45.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "46.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "46.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "47.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "47.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "47.0.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "suse",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_enterprise_debuginfo",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "studio_onsite",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux_enterprise_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux_enterprise_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "linux_enterprise_software_development_kit",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "12.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html",
          "name" : "APPLE-SA-2016-07-18-1",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00064.html",
          "name" : "openSUSE-SU-2016:1441",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00006.html",
          "name" : "SUSE-SU-2016:1508",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00007.html",
          "name" : "SUSE-SU-2016:1512",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00010.html",
          "name" : "openSUSE-SU-2016:1523",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html",
          "name" : "openSUSE-SU-2016:1964",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00029.html",
          "name" : "openSUSE-SU-2016:2026",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.html",
          "name" : "http://packetstormsecurity.com/files/141350/ESET-Endpoint-Antivirus-6-Remote-Code-Execution.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2824.html",
          "name" : "RHSA-2016:2824",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2017/Feb/68",
          "name" : "20170227 CVE-2016-9892 - Remote Code Execution as Root via ESET Endpoint Antivirus 6",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://support.eset.com/ca6333/",
          "name" : "http://support.eset.com/ca6333/",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3582",
          "name" : "DSA-3582",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.mozilla.org/security/announce/2016/mfsa2016-68.html",
          "name" : "http://www.mozilla.org/security/announce/2016/mfsa2016-68.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/05/17/12",
          "name" : "[oss-security] 20160517 CVE-2016-0718: Expat XML Parser Crashes on Malformed Input",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/90729",
          "name" : "90729",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036348",
          "name" : "1036348",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1036415",
          "name" : "1036415",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037705",
          "name" : "1037705",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2983-1",
          "name" : "USN-2983-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-3044-1",
          "name" : "USN-3044-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2018:2486",
          "name" : "RHSA-2018:2486",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.mozilla.org/show_bug.cgi?id=1236923",
          "name" : "https://bugzilla.mozilla.org/show_bug.cgi?id=1236923",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1296102",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1296102",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201701-21",
          "name" : "GLSA-201701-21",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://source.android.com/security/bulletin/2016-11-01.html",
          "name" : "https://source.android.com/security/bulletin/2016-11-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://support.apple.com/HT206903",
          "name" : "https://support.apple.com/HT206903",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.tenable.com/security/tns-2016-20",
          "name" : "https://www.tenable.com/security/tns-2016-20",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "48.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.11.0",
          "versionEndIncluding" : "10.11.5"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_desktop:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_desktop:12.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_server:12.0:sp1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:suse:linux_enterprise_software_development_kit:12.0:sp1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libexpat:expat:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "2.2.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-26T16:59Z",
    "lastModifiedDate" : "2018-11-16T16:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0719",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2016-0718.  Reason: This candidate is a reservation duplicate of CVE-2016-0718.  Notes: All CVE users should reference CVE-2016-0718 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2016-05-18T15:59Z",
    "lastModifiedDate" : "2016-05-18T15:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0720",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clusterlabs",
            "product" : {
              "product_data" : [ {
                "product_name" : "pcs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.148",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-352"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178261.html",
          "name" : "FEDORA-2016-3b20c4ec9d",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178384.html",
          "name" : "FEDORA-2016-cdd4228cc7",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2596.html",
          "name" : "RHSA-2016:2596",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/97984",
          "name" : "97984",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1299614",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1299614",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://github.com/ClusterLabs/pcs/commit/b9e7f061788c3b86a0c67d2d4158f067ec5eb625",
          "name" : "https://github.com/ClusterLabs/pcs/commit/b9e7f061788c3b86a0c67d2d4158f067ec5eb625",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clusterlabs:pcs:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.148"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-04-21T15:59Z",
    "lastModifiedDate" : "2017-04-27T13:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0721",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "clusterlabs",
            "product" : {
              "product_data" : [ {
                "product_name" : "pcs",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.156",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-384"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178261.html",
          "name" : "FEDORA-2016-3b20c4ec9d",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178384.html",
          "name" : "FEDORA-2016-cdd4228cc7",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2596.html",
          "name" : "RHSA-2016:2596",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/97977",
          "name" : "97977",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1299615",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1299615",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Patch", "Third Party Advisory" ]
        }, {
          "url" : "https://github.com/ClusterLabs/pcs/commit/acdbbe8307e6f4a36b2c7754765e732e43fe8d17",
          "name" : "https://github.com/ClusterLabs/pcs/commit/acdbbe8307e6f4a36b2c7754765e732e43fe8d17",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://github.com/ClusterLabs/pcs/commit/bc6ad9086857559db57f4e3e6de66762291c0774",
          "name" : "https://github.com/ClusterLabs/pcs/commit/bc6ad9086857559db57f4e3e6de66762291c0774",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://github.com/ClusterLabs/pcs/commit/e9b28833d54a47ec441f6dbad0db96e1fc662a5b",
          "name" : "https://github.com/ClusterLabs/pcs/commit/e9b28833d54a47ec441f6dbad0db96e1fc662a5b",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Session fixation vulnerability in pcsd in pcs before 0.9.157."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:clusterlabs:pcs:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.156"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-04-21T15:59Z",
    "lastModifiedDate" : "2017-04-27T16:15Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0722",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2016-02-18T15:59Z",
    "lastModifiedDate" : "2016-02-18T15:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0723",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          }, {
            "lang" : "en",
            "value" : "CWE-362"
          }, {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5c17c861a357e9458001f021a7afa7aab9937439",
          "name" : "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5c17c861a357e9458001f021a7afa7aab9937439",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176464.html",
          "name" : "FEDORA-2016-2f25d12c51",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.html",
          "name" : "FEDORA-2016-5d43766e33",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00094.html",
          "name" : "SUSE-SU-2016:0911",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00015.html",
          "name" : "openSUSE-SU-2016:1008",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00045.html",
          "name" : "SUSE-SU-2016:1102",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00005.html",
          "name" : "SUSE-SU-2016:1764",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00038.html",
          "name" : "SUSE-SU-2016:2074",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-07-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-07-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3448",
          "name" : "DSA-3448",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3503",
          "name" : "DSA-3503",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82950",
          "name" : "82950",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035695",
          "name" : "1035695",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2929-1",
          "name" : "USN-2929-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2929-2",
          "name" : "USN-2929-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2930-1",
          "name" : "USN-2930-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2930-2",
          "name" : "USN-2930-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2930-3",
          "name" : "USN-2930-3",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2932-1",
          "name" : "USN-2932-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2948-1",
          "name" : "USN-2948-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2948-2",
          "name" : "USN-2948-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2967-1",
          "name" : "USN-2967-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2967-2",
          "name" : "USN-2967-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1296253",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1296253",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://github.com/torvalds/linux/commit/5c17c861a357e9458001f021a7afa7aab9937439",
          "name" : "https://github.com/torvalds/linux/commit/5c17c861a357e9458001f021a7afa7aab9937439",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security-tracker.debian.org/tracker/CVE-2016-0723",
          "name" : "https://security-tracker.debian.org/tracker/CVE-2016-0723",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.f5.com/csp/article/K43650115",
          "name" : "https://support.f5.com/csp/article/K43650115",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/416.html\">CWE-416: Use After Free</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.4.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.8,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 5.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 7.8,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-08T03:59Z",
    "lastModifiedDate" : "2016-12-06T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0724",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moodle",
            "product" : {
              "product_data" : [ {
                "product_name" : "moodle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.6.11",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          }, {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52072",
          "name" : "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52072",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176502.html",
          "name" : "FEDORA-2016-fb2597f4eb",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176436.html",
          "name" : "FEDORA-2016-1c10ab3c35",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/18/1",
          "name" : "[oss-security] 20160118 [vs] moodle security release",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034694",
          "name" : "1034694",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://moodle.org/mod/forum/discuss.php?d=326205",
          "name" : "https://moodle.org/mod/forum/discuss.php?d=326205",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a web-service request."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.6.11"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.7.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:3.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-22T05:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0725",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "moodle",
            "product" : {
              "product_data" : [ {
                "product_name" : "moodle",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.8.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52552",
          "name" : "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52552",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176502.html",
          "name" : "FEDORA-2016-fb2597f4eb",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176436.html",
          "name" : "FEDORA-2016-1c10ab3c35",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/18/1",
          "name" : "[oss-security] 20160118 [vs] moodle security release",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034694",
          "name" : "1034694",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://moodle.org/mod/forum/discuss.php?d=326206",
          "name" : "https://moodle.org/mod/forum/discuss.php?d=326206",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.8.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:2.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:moodle:moodle:3.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-22T05:59Z",
    "lastModifiedDate" : "2017-09-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0726",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nagios",
            "product" : {
              "product_data" : [ {
                "product_name" : "nagios",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-798"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1295446",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1295446",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Fedora Nagios package uses \"nagiosadmin\" as the default password for the \"nagiosadmin\" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nagios:nagios:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-06-06T18:29Z",
    "lastModifiedDate" : "2017-06-22T18:32Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0727",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/141913/NTP-Privilege-Escalation.html",
          "name" : "http://packetstormsecurity.com/files/141913/NTP-Privilege-Escalation.html",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81552",
          "name" : "81552",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034808",
          "name" : "1034808",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-3096-1",
          "name" : "USN-3096-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/1528050",
          "name" : "https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/1528050",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1382369",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1382369",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics directory cleanup."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : true,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-04-14T18:59Z",
    "lastModifiedDate" : "2017-04-20T16:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0728",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "server_migration_pack",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.5",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23567fd052a9abb6d67fe8e7a9ccdd9800a540f2",
          "name" : "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23567fd052a9abb6d67fe8e7a9ccdd9800a540f2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176484.html",
          "name" : "FEDORA-2016-5d43766e33",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176194.html",
          "name" : "FEDORA-2016-b59fd603be",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00026.html",
          "name" : "SUSE-SU-2016:0205",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00012.html",
          "name" : "SUSE-SU-2016:0341",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00033.html",
          "name" : "SUSE-SU-2016:0745",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00034.html",
          "name" : "SUSE-SU-2016:0746",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00035.html",
          "name" : "SUSE-SU-2016:0747",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00038.html",
          "name" : "SUSE-SU-2016:0750",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00039.html",
          "name" : "SUSE-SU-2016:0751",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00040.html",
          "name" : "SUSE-SU-2016:0752",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00041.html",
          "name" : "SUSE-SU-2016:0753",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00043.html",
          "name" : "SUSE-SU-2016:0755",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00044.html",
          "name" : "SUSE-SU-2016:0756",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00045.html",
          "name" : "SUSE-SU-2016:0757",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/",
          "name" : "http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0064.html",
          "name" : "RHSA-2016:0064",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0065.html",
          "name" : "RHSA-2016:0065",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0068.html",
          "name" : "RHSA-2016:0068",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-03-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-03-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3448",
          "name" : "DSA-3448",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1",
          "name" : "http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/19/2",
          "name" : "[oss-security] 20160119 Linux kernel: use after free in keyring facility.",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81054",
          "name" : "81054",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034701",
          "name" : "1034701",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2870-1",
          "name" : "USN-2870-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2870-2",
          "name" : "USN-2870-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2871-1",
          "name" : "USN-2871-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2871-2",
          "name" : "USN-2871-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2872-1",
          "name" : "USN-2872-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2872-2",
          "name" : "USN-2872-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2872-3",
          "name" : "USN-2872-3",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2873-1",
          "name" : "USN-2873-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa112",
          "name" : "https://bto.bluecoat.com/security-advisory/sa112",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1297475",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1297475",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://github.com/torvalds/linux/commit/23567fd052a9abb6d67fe8e7a9ccdd9800a540f2",
          "name" : "https://github.com/torvalds/linux/commit/23567fd052a9abb6d67fe8e7a9ccdd9800a540f2",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05018265",
          "name" : "HPSBHF03436",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05130958",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05130958",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160211-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160211-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39277/",
          "name" : "39277",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/190.html\">CWE-190: Integer Overflow or Wraparound</a> <br />\n\n<a href=\"http://cwe.mitre.org/data/definitions/416.html\">CWE-416: Use After Free</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:server_migration_pack:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.5"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.4"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-08T03:59Z",
    "lastModifiedDate" : "2017-11-10T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0729",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "xerces-c\\+\\+",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "24",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182062.html",
          "name" : "FEDORA-2016-9ff972ca42",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182131.html",
          "name" : "FEDORA-2016-ae9ac16cf3",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182597.html",
          "name" : "FEDORA-2016-880b91c090",
          "refsource" : "FEDORA",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-04/msg00012.html",
          "name" : "openSUSE-SU-2016:0966",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-04/msg00086.html",
          "name" : "openSUSE-SU-2016:1121",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-07/msg00053.html",
          "name" : "openSUSE-SU-2016:1808",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://packetstormsecurity.com/files/135949/Apache-Xerces-C-XML-Parser-Buffer-Overflow.html",
          "name" : "http://packetstormsecurity.com/files/135949/Apache-Xerces-C-XML-Parser-Buffer-Overflow.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1727978",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1727978",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3493",
          "name" : "DSA-3493",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537620/100/0/threaded",
          "name" : "20160225 CVE-2016-0729: Apache Xerces-C XML Parser Crashes on Malformed Input",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83423",
          "name" : "83423",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035113",
          "name" : "1035113",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://xerces.apache.org/xerces-c/secadv/CVE-2016-0729.txt",
          "name" : "http://xerces.apache.org/xerces-c/secadv/CVE-2016-0729.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://issues.apache.org/jira/browse/XERCESC-2061",
          "name" : "https://issues.apache.org/jira/browse/XERCESC-2061",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201612-46",
          "name" : "GLSA-201612-46",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
          "name" : "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
          "refsource" : "MISC",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:xerces-c\\\\\\+\\\\\\+:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.2"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-07T21:59Z",
    "lastModifiedDate" : "2018-10-17T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0730",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-02-04T18:59Z",
    "lastModifiedDate" : "2017-02-04T18:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0731",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "ambari",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.2.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.2.1",
          "name" : "https://cwiki.apache.org/confluence/display/AMBARI/Ambari+Vulnerabilities#AmbariVulnerabilities-FixedinAmbari2.2.1",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_releasenotes_ambari_2.2.1.0/content/ambari_relnotes-2.2.1.0-cves.html",
          "name" : "https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_releasenotes_ambari_2.2.1.0/content/ambari_relnotes-2.2.1.0-cves.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://issues.apache.org/jira/browse/AMBARI-14780",
          "name" : "https://issues.apache.org/jira/browse/AMBARI-14780",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.2.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "HIGH",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-05-18T14:59Z",
    "lastModifiedDate" : "2016-05-18T21:34Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0732",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pivotal",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_foundry",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "208",
                    "version_affected" : "="
                  }, {
                    "version_value" : "229",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "elastic_runtime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.13",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "uaa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.7.3",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "uaa-release",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://pivotal.io/security/cve-2016-0732",
          "name" : "https://pivotal.io/security/cve-2016-0732",
          "refsource" : "CONFIRM",
          "tags" : [ "Mitigation", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:cloud_foundry:208:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:cloud_foundry:229:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa:2.7.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa-release:2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa-release:3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:uaa-release:4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal:elastic_runtime:1.6.13:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-09-07T13:29Z",
    "lastModifiedDate" : "2017-09-18T18:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0733",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "ranger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/82871",
          "name" : "82871",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
          "name" : "https://cwiki.apache.org/confluence/display/RANGER/Vulnerabilities+found+in+Ranger",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://issues.apache.org/jira/browse/RANGER-835",
          "name" : "https://issues.apache.org/jira/browse/RANGER-835",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://mail-archives.apache.org/mod_mbox/ranger-dev/201602.mbox/%3CD2D9A4C5.114ECA%25vel@apache.org%3E",
          "name" : "[ranger-dev] 20160205 CVE update (CVE-2015-5167 & CVE-2016-0733) - Fixed in Ranger 0.5.1",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-12T14:59Z",
    "lastModifiedDate" : "2016-04-19T03:44Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0734",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "activemq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.13.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://activemq.apache.org/security-advisories.data/CVE-2016-0734-announcement.txt",
          "name" : "http://activemq.apache.org/security-advisories.data/CVE-2016-0734-announcement.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/03/10/11",
          "name" : "[oss-security] 20160310 [ANNOUNCE] CVE-2016-0734: ActiveMQ Web Console - Clickjacking",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/84321",
          "name" : "84321",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035327",
          "name" : "1035327",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1424",
          "name" : "RHSA-2016:1424",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E",
          "name" : "[activemq-commits] 20190327 svn commit: r1042639 - in /websites/production/activemq/content/activemq-website: ./ projects/artemis/download/ projects/classic/download/ projects/cms/download/ security-advisories.data/",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.13.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-07T19:59Z",
    "lastModifiedDate" : "2019-03-27T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0735",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "ranger",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://mail-archives.apache.org/mod_mbox/ranger-dev/201603.mbox/%3CD31EE434.14B879%25vel%40apache.org%3E",
          "name" : "[ranger-dev] 20160328 CVE update (CVE-2016-0735) - Fixed in Ranger 0.5.2",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:ranger:0.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:ranger:0.5.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-11T19:59Z",
    "lastModifiedDate" : "2016-04-19T14:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0736",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "http_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.4.23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2017-1415.html",
          "name" : "RHSA-2017:1415",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2017/dsa-3796",
          "name" : "DSA-3796",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/95078",
          "name" : "95078",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037508",
          "name" : "1037508",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:0906",
          "name" : "RHSA-2017:0906",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1161",
          "name" : "RHSA-2017:1161",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1413",
          "name" : "RHSA-2017:1413",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:1414",
          "name" : "RHSA-2017:1414",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-0736",
          "name" : "https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-0736",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048743 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20190815 svn commit: r1048742 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058586 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234@%3Ccvs.httpd.apache.org%3E",
          "name" : "[httpd-cvs] 20200401 svn commit: r1058587 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201701-36",
          "name" : "GLSA-201701-36",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20180423-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20180423-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT208221",
          "name" : "https://support.apple.com/HT208221",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40961/",
          "name" : "40961",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.tenable.com/security/tns-2017-04",
          "name" : "https://www.tenable.com/security/tns-2017-04",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:http_server:2.4.23:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-07-27T21:29Z",
    "lastModifiedDate" : "2018-04-25T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0737",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openstack",
            "product" : {
              "product_data" : [ {
                "product_name" : "swift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0128.html",
          "name" : "RHSA-2016:0128",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0155.html",
          "name" : "RHSA-2016:0155",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0329.html",
          "name" : "RHSA-2016:0329",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81432",
          "name" : "81432",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugs.launchpad.net/swift/+bug/1466549",
          "name" : "https://bugs.launchpad.net/swift/+bug/1466549",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://launchpad.net/swift/+milestone/2.4.0",
          "name" : "https://launchpad.net/swift/+milestone/2.4.0",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://review.openstack.org/#/c/217750/",
          "name" : "https://review.openstack.org/#/c/217750/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.openstack.org/ossa/OSSA-2016-004.html",
          "name" : "https://security.openstack.org/ossa/OSSA-2016-004.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-29T20:59Z",
    "lastModifiedDate" : "2016-12-03T03:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0738",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openstack",
            "product" : {
              "product_data" : [ {
                "product_name" : "swift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.3.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "2.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.5.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176713.html",
          "name" : "FEDORA-2016-2256c80a94",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0128.html",
          "name" : "RHSA-2016:0128",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0155.html",
          "name" : "RHSA-2016:0155",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0329.html",
          "name" : "RHSA-2016:0329",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81432",
          "name" : "81432",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bugs.launchpad.net/cloud-archive/+bug/1493303",
          "name" : "https://bugs.launchpad.net/cloud-archive/+bug/1493303",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://github.com/openstack/swift/blob/master/CHANGELOG",
          "name" : "https://github.com/openstack/swift/blob/master/CHANGELOG",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://security.openstack.org/ossa/OSSA-2016-004.html",
          "name" : "https://security.openstack.org/ossa/OSSA-2016-004.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.3.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:swift:2.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:swift:2.5.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-29T20:59Z",
    "lastModifiedDate" : "2016-12-06T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0739",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libssh",
            "product" : {
              "product_data" : [ {
                "product_name" : "libssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.7.2",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178058.html",
          "name" : "FEDORA-2016-d9f950c779",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178822.html",
          "name" : "FEDORA-2016-dc9e8da03c",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-03/msg00111.html",
          "name" : "openSUSE-SU-2016:0880",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0566.html",
          "name" : "RHSA-2016:0566",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3488",
          "name" : "DSA-3488",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2912-1",
          "name" : "USN-2912-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://puppet.com/security/cve/CVE-2016-0739",
          "name" : "https://puppet.com/security/cve/CVE-2016-0739",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-12",
          "name" : "GLSA-201606-12",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.libssh.org/2016/02/23/libssh-0-7-3-security-and-bugfix-release/",
          "name" : "https://www.libssh.org/2016/02/23/libssh-0-7-3-security-and-bugfix-release/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.libssh.org/security/advisories/CVE-2016-0739.txt",
          "name" : "https://www.libssh.org/security/advisories/CVE-2016-0739.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a \"bits/bytes confusion bug.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.7.2"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-13T17:59Z",
    "lastModifiedDate" : "2017-12-09T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0740",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "python",
            "product" : {
              "product_data" : [ {
                "product_name" : "pillow",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.debian.org/security/2016/dsa-3499",
          "name" : "DSA-3499",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst",
          "name" : "https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://github.com/python-pillow/Pillow/commit/6dcbf5bd96b717c58d7b642949da8d323099928e",
          "name" : "https://github.com/python-pillow/Pillow/commit/6dcbf5bd96b717c58d7b642949da8d323099928e",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201612-52",
          "name" : "GLSA-201612-52",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-13T16:59Z",
    "lastModifiedDate" : "2017-07-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0741",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "389_directory_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.3.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-4-7.html",
          "name" : "http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-4-7.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0204.html",
          "name" : "RHSA-2016:0204",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82343",
          "name" : "82343",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://fedorahosted.org/389/changeset/cd45d032421b0ecf76d8cbb9b1c3aeef7680d9a2/",
          "name" : "https://fedorahosted.org/389/changeset/cd45d032421b0ecf76d8cbb9b1c3aeef7680d9a2/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://fedorahosted.org/389/ticket/48412",
          "name" : "https://fedorahosted.org/389/ticket/48412",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fedoraproject:389_directory_server:1.3.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fedoraproject:389_directory_server:1.3.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fedoraproject:389_directory_server:1.3.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:fedoraproject:389_directory_server:1.3.4.5:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-19T21:59Z",
    "lastModifiedDate" : "2016-10-12T02:01Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0742",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nginx",
            "product" : {
              "product_data" : [ {
                "product_name" : "nginx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html",
          "name" : "openSUSE-SU-2016:0371",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html",
          "name" : "[nginx] 20160126 nginx security advisory (CVE-2016-0742, CVE-2016-0746, CVE-2016-0747)",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3473",
          "name" : "DSA-3473",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034869",
          "name" : "1034869",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2892-1",
          "name" : "USN-2892-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1425",
          "name" : "RHSA-2016:1425",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa115",
          "name" : "https://bto.bluecoat.com/security-advisory/sa115",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1302587",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1302587",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-06",
          "name" : "GLSA-201606-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response."
        }, {
          "lang" : "en",
          "value" : "<a href=\"https://cwe.mitre.org/data/definitions/476.html\">CWE-476: NULL Pointer Dereference</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-15T19:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0746",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nginx",
            "product" : {
              "product_data" : [ {
                "product_name" : "nginx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.6.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.7.69",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.51",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.8.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "0.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.4.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.7.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html",
          "name" : "openSUSE-SU-2016:0371",
          "refsource" : "SUSE",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html",
          "name" : "[nginx] 20160126 nginx security advisory (CVE-2016-0742, CVE-2016-0746, CVE-2016-0747)",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3473",
          "name" : "DSA-3473",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034869",
          "name" : "1034869",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2892-1",
          "name" : "USN-2892-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Broken Link" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1425",
          "name" : "RHSA-2016:1425",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa115",
          "name" : "https://bto.bluecoat.com/security-advisory/sa115",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1302588",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1302588",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-06",
          "name" : "GLSA-201606-06",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/416.html\" rel=\"nofollow\">CWE-416: Use After Free</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "0.6.18",
          "versionEndIncluding" : "1.8.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.9:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 7.3,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-15T19:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0747",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "nginx",
            "product" : {
              "product_data" : [ {
                "product_name" : "nginx",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.8.0",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.9.9",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html",
          "name" : "openSUSE-SU-2016:0371",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html",
          "name" : "[nginx] 20160126 nginx security advisory (CVE-2016-0742, CVE-2016-0746, CVE-2016-0747)",
          "refsource" : "MLIST",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3473",
          "name" : "DSA-3473",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034869",
          "name" : "1034869",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2892-1",
          "name" : "USN-2892-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1425",
          "name" : "RHSA-2016:1425",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa115",
          "name" : "https://bto.bluecoat.com/security-advisory/sa115",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1302589",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1302589",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-06",
          "name" : "GLSA-201606-06",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.8.0"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:nginx:nginx:1.9.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "LOW",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-15T19:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0749",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "spice_project",
            "product" : {
              "product_data" : [ {
                "product_name" : "spice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "leap",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "42.1",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-07/msg00003.html",
          "name" : "openSUSE-SU-2016:1725",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-07/msg00004.html",
          "name" : "openSUSE-SU-2016:1726",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3596",
          "name" : "DSA-3596",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-3014-1",
          "name" : "USN-3014-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1204",
          "name" : "RHSA-2016:1204",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1205",
          "name" : "RHSA-2016:1205",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-05",
          "name" : "GLSA-201606-05",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:scientific_computing:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:scientific_computing:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:spice_project:spice:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-09T16:59Z",
    "lastModifiedDate" : "2019-04-22T17:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0750",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "infinispan",
            "product" : {
              "product_data" : [ {
                "product_name" : "infinispan",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-502"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.securityfocus.com/bid/101910",
          "name" : "101910",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:3244",
          "name" : "RHSA-2017:3244",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2018:0501",
          "name" : "RHSA-2018:0501",
          "refsource" : "REDHAT",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-0750",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Vendor Advisory" ]
        }, {
          "url" : "https://github.com/infinispan/infinispan/pull/5116",
          "name" : "https://github.com/infinispan/infinispan/pull/5116",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://issues.jboss.org/browse/ISPN-7781",
          "name" : "https://issues.jboss.org/browse/ISPN-7781",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:infinispan:infinispan:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "9.1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2018-09-11T13:29Z",
    "lastModifiedDate" : "2019-10-09T23:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0751",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rubyonrails",
            "product" : {
              "product_data" : [ {
                "product_name" : "rails",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ruby_on_rails",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.22",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178043.html",
          "name" : "FEDORA-2016-94e71ee673",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178067.html",
          "name" : "FEDORA-2016-f486068393",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html",
          "name" : "SUSE-SU-2016:1146",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html",
          "name" : "openSUSE-SU-2016:0363",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html",
          "name" : "openSUSE-SU-2016:0372",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0296.html",
          "name" : "RHSA-2016:0296",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3464",
          "name" : "DSA-3464",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/25/9",
          "name" : "[oss-security] 20160125 [CVE-2016-0751] Possible Object Leak and Denial of Service attack in Action Pack",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81800",
          "name" : "81800",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034816",
          "name" : "1034816",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://groups.google.com/forum/message/raw?msg=ruby-security-ann/9oLY_FCzvoc/5CDXbvpYEgAJ",
          "name" : "[ruby-security-ann] 20160125 [CVE-2016-0751] Possible Object Leak and Denial of Service attack in Action Pack",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.10:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.4:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:5.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.2.22"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.10:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.0.13:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-16T02:59Z",
    "lastModifiedDate" : "2019-08-08T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0752",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rubyonrails",
            "product" : {
              "product_data" : [ {
                "product_name" : "rails",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ruby_on_rails",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.2.22",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "4.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178044.html",
          "name" : "FEDORA-2016-fa0dec2360",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178069.html",
          "name" : "FEDORA-2016-97002ad37b",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html",
          "name" : "SUSE-SU-2016:1146",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html",
          "name" : "openSUSE-SU-2016:0363",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html",
          "name" : "openSUSE-SU-2016:0372",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0296.html",
          "name" : "RHSA-2016:0296",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3464",
          "name" : "DSA-3464",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/25/13",
          "name" : "[oss-security] 20160125 [CVE-2016-0752] Possible Information Leak Vulnerability in Action View",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/81801",
          "name" : "81801",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034816",
          "name" : "1034816",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://groups.google.com/forum/message/raw?msg=ruby-security-ann/335P1DcLG00/JXcBnTtZEgAJ",
          "name" : "[ruby-security-ann] 20160125 [CVE-2016-0752] Possible Information Leak Vulnerability in Action View",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/40561/",
          "name" : "40561",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.1:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.6:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.0.10:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.4:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:5.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.2.22"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-16T02:59Z",
    "lastModifiedDate" : "2019-08-08T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0753",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "rubyonrails",
            "product" : {
              "product_data" : [ {
                "product_name" : "rails",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "ruby_on_rails",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.1.11",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178041.html",
          "name" : "FEDORA-2016-73fe05d878",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178043.html",
          "name" : "FEDORA-2016-94e71ee673",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178047.html",
          "name" : "FEDORA-2016-cb30088b06",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178065.html",
          "name" : "FEDORA-2016-cc465a34df",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178066.html",
          "name" : "FEDORA-2016-eb4d6e8aab",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html",
          "name" : "SUSE-SU-2016:1146",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html",
          "name" : "openSUSE-SU-2016:0372",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0296.html",
          "name" : "RHSA-2016:0296",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3464",
          "name" : "DSA-3464",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/25/14",
          "name" : "[oss-security] 20160125 [CVE-2016-0753] Possible Input Validation Circumvention in Active Model",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82247",
          "name" : "82247",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034816",
          "name" : "1034816",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://groups.google.com/forum/message/raw?msg=ruby-security-ann/6jQVC1geukQ/3Iy0GU1ZEgAJ",
          "name" : "[ruby-security-ann] 20160125 [CVE-2016-0753] Possible Input Validation Circumvention in Active Model",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.0:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.2:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.6:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:beta4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.1:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.3:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.4:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:4.2.5:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:rails:5.0.0:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:rubyonrails:ruby_on_rails:4.1.11:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-16T02:59Z",
    "lastModifiedDate" : "2019-08-08T15:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0754",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "haxx",
            "product" : {
              "product_data" : [ {
                "product_name" : "curl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.46.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://curl.haxx.se/docs/adv_20160127B.html",
          "name" : "http://curl.haxx.se/docs/adv_20160127B.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "7.46.0"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-29T20:59Z",
    "lastModifiedDate" : "2016-02-17T15:56Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0755",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "haxx",
            "product" : {
              "product_data" : [ {
                "product_name" : "curl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.46.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-287"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://curl.haxx.se/docs/adv_20160127A.html",
          "name" : "http://curl.haxx.se/docs/adv_20160127A.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html",
          "name" : "APPLE-SA-2016-09-20",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176546.html",
          "name" : "FEDORA-2016-3fa315a5dd",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177342.html",
          "name" : "FEDORA-2016-55137a3adb",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177383.html",
          "name" : "FEDORA-2016-5a141de5d9",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176413.html",
          "name" : "FEDORA-2016-57bebab3b6",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00031.html",
          "name" : "openSUSE-SU-2016:0360",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00044.html",
          "name" : "openSUSE-SU-2016:0373",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-02/msg00047.html",
          "name" : "openSUSE-SU-2016:0376",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://packetstormsecurity.com/files/135695/Slackware-Security-Advisory-curl-Updates.html",
          "name" : "http://packetstormsecurity.com/files/135695/Slackware-Security-Advisory-curl-Updates.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3455",
          "name" : "DSA-3455",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82307",
          "name" : "82307",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034882",
          "name" : "1034882",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.519965",
          "name" : "SSA:2016-039-01",
          "refsource" : "SLACKWARE",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2882-1",
          "name" : "USN-2882-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201701-47",
          "name" : "GLSA-201701-47",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT207170",
          "name" : "https://support.apple.com/HT207170",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "7.46.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 7.3,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-29T20:59Z",
    "lastModifiedDate" : "2018-10-17T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0756",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "prosody",
            "product" : {
              "product_data" : [ {
                "product_name" : "prosody",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.9.9",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://blog.prosody.im/prosody-0-9-10-released/",
          "name" : "http://blog.prosody.im/prosody-0-9-10-released/",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176796.html",
          "name" : "FEDORA-2016-e2c5111eda",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176914.html",
          "name" : "FEDORA-2016-5a5c85c5a8",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3463",
          "name" : "DSA-3463",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/27/10",
          "name" : "[oss-security] 20160127 CVE-2016-0756: Prosody XMPP server: insecure dialback key generation/validation algorithm",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82241",
          "name" : "82241",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://prosody.im/issues/issue/596",
          "name" : "https://prosody.im/issues/issue/596",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://prosody.im/security/advisory_20160127/",
          "name" : "https://prosody.im/security/advisory_20160127/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.9.9"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-01-29T20:59Z",
    "lastModifiedDate" : "2016-12-06T03:05Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0757",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openstack",
            "product" : {
              "product_data" : [ {
                "product_name" : "image_registry_and_delivery_service_(glance)",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "11.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2015.1.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0309.html",
          "name" : "RHSA-2016:0309",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82696",
          "name" : "82696",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://security.openstack.org/ossa/OSSA-2016-006.html",
          "name" : "https://security.openstack.org/ossa/OSSA-2016-006.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):11.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):11.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2015.1.2:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-13T17:59Z",
    "lastModifiedDate" : "2016-11-28T19:55Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0758",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.5.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "enterprise_linux_desktop",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_hpc_node_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_aus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_server_eus",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.2",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "enterprise_linux_workstation",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa",
          "name" : "http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00044.html",
          "name" : "openSUSE-SU-2016:1641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00052.html",
          "name" : "SUSE-SU-2016:1672",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00054.html",
          "name" : "SUSE-SU-2016:1690",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html",
          "name" : "SUSE-SU-2016:1937",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html",
          "name" : "SUSE-SU-2016:1961",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html",
          "name" : "SUSE-SU-2016:1985",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html",
          "name" : "SUSE-SU-2016:1994",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html",
          "name" : "SUSE-SU-2016:1995",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html",
          "name" : "SUSE-SU-2016:2000",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html",
          "name" : "SUSE-SU-2016:2001",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html",
          "name" : "SUSE-SU-2016:2002",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00017.html",
          "name" : "SUSE-SU-2016:2003",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html",
          "name" : "SUSE-SU-2016:2005",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html",
          "name" : "SUSE-SU-2016:2006",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html",
          "name" : "SUSE-SU-2016:2007",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html",
          "name" : "SUSE-SU-2016:2009",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html",
          "name" : "SUSE-SU-2016:2010",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00023.html",
          "name" : "SUSE-SU-2016:2011",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html",
          "name" : "SUSE-SU-2016:2014",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html",
          "name" : "SUSE-SU-2016:2105",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html",
          "name" : "openSUSE-SU-2016:2184",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1033.html",
          "name" : "RHSA-2016:1033",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1051.html",
          "name" : "RHSA-2016:1051",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1055.html",
          "name" : "RHSA-2016:1055",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-10-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-10-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/05/12/9",
          "name" : "[oss-security] 20160513 CVE-2016-0758 - Linux kernel - Flaw in ASN.1 DER decoder for x509 certificate DER files.",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/90626",
          "name" : "90626",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2979-4",
          "name" : "USN-2979-4",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1300257",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1300257",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://github.com/torvalds/linux/commit/23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa",
          "name" : "https://github.com/torvalds/linux/commit/23c8a812dc3c621009e4f0e5342aa4e2ede1ceaa",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158555",
          "name" : "HPSBHF3548",
          "refsource" : "HP",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/190.html\">CWE-190: Integer Overflow or Wraparound</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "4.5.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-06-27T10:59Z",
    "lastModifiedDate" : "2016-11-28T19:55Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0759",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2016-4003.  Reason: This candidate is a reservation duplicate of CVE-2016-4003.  Notes: All CVE users should reference CVE-2016-4003 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-10-31T14:29Z",
    "lastModifiedDate" : "2017-10-31T14:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0760",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "sentry",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://mail-archives.apache.org/mod_mbox/sentry-dev/201608.mbox/%3CCACMN7ixDqDyOZGLEvsMUVHBiJ6crq8zdy%2B2mNfRooNhnk7CJ1g%40mail.gmail.com%3E",
          "name" : "[sentry-dev] 20160804 CVE-2016-0760: Hive builtin functions \"reflect\", \"reflect2\", and \"java_method\" are not blocked in Apache Sentry",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/92328",
          "name" : "92328",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) java_method Hive builtin functions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:sentry:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:sentry:1.6.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-08-19T21:59Z",
    "lastModifiedDate" : "2016-08-22T17:43Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0761",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pivotal_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_foundry_elastic_runtime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.16",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cloud_foundry_garden_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "0.332.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-19"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://pivotal.io/security/cve-2016-0761",
          "name" : "https://pivotal.io/security/cve-2016-0761",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_garden_linux:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "0.332.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-05-25T17:29Z",
    "lastModifiedDate" : "2017-06-08T13:42Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0762",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.38",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.43",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.44",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.45",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.46",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.48",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.49",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.58",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.60",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.66",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.68",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.69",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.70",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.31",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.36",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2017-0457.html",
          "name" : "RHSA-2017:0457",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3720",
          "name" : "DSA-3720",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/93939",
          "name" : "93939",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1037144",
          "name" : "1037144",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:0455",
          "name" : "RHSA-2017:0455",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:0456",
          "name" : "RHSA-2017:0456",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2017:2247",
          "name" : "RHSA-2017:2247",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/1872f96bad43647832bdd84a408794cd06d9cbb557af63085ca10009@%3Cannounce.tomcat.apache.org%3E",
          "name" : "[announce] 20161027 [SECURITY] CVE-2016-0762 Apache Tomcat Realm Timing Attack",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Vendor Advisory" ]
        }, {
          "url" : "https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [25/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190413 svn commit: r1857494 [15/20] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [22/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [21/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190415 svn commit: r1857582 [17/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/845312a10aabbe2c499fca94003881d2c79fc993d85f34c1f5c77424@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190413 svn commit: r1857494 [16/20] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190325 svn commit: r1856174 [24/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190415 svn commit: r1857582 [16/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [23/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200203 svn commit: r1873527 [23/30] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [26/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [27/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20180605-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20180605-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:6.0.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.38:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.43:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.44:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.45:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.46:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.48:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.49:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.58:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.60:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.66:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.68:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.69:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.70:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.31:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.36:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m6:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m7:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m8:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m9:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-08-10T16:29Z",
    "lastModifiedDate" : "2019-04-15T16:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0763",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomcat",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.25",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.32",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.33",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.34",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.35",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.37",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.39",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.40",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.41",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.42",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.47",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.50",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.52",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.53",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.54",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.55",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.56",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.57",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.59",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.61",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.62",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.63",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.64",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.65",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0.67",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.26",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.27",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.28",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.29",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0.30",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "16.04",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/179356.html",
          "name" : "FEDORA-2016-e6651efbaf",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html",
          "name" : "SUSE-SU-2016:0769",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html",
          "name" : "SUSE-SU-2016:0822",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html",
          "name" : "openSUSE-SU-2016:0865",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1089.html",
          "name" : "RHSA-2016:1089",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2599.html",
          "name" : "RHSA-2016:2599",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2807.html",
          "name" : "RHSA-2016:2807",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2808.html",
          "name" : "RHSA-2016:2808",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://seclists.org/bugtraq/2016/Feb/147",
          "name" : "20160222 [SECURITY] CVE-2016-0763 Apache Tomcat Security Manager Bypass",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1725926",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1725926",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1725929",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1725929",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://svn.apache.org/viewvc?view=revision&revision=1725931",
          "name" : "http://svn.apache.org/viewvc?view=revision&revision=1725931",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://tomcat.apache.org/security-7.html",
          "name" : "http://tomcat.apache.org/security-7.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-8.html",
          "name" : "http://tomcat.apache.org/security-8.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tomcat.apache.org/security-9.html",
          "name" : "http://tomcat.apache.org/security-9.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3530",
          "name" : "DSA-3530",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3552",
          "name" : "DSA-3552",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3609",
          "name" : "DSA-3609",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83326",
          "name" : "83326",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035069",
          "name" : "1035069",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-3024-1",
          "name" : "USN-3024-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1087",
          "name" : "RHSA-2016:1087",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1088",
          "name" : "RHSA-2016:1088",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa118",
          "name" : "https://bto.bluecoat.com/security-advisory/sa118",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20190319 svn commit: r1855831 [25/30] - in /tomcat/site/trunk: ./ docs/ xdocs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E",
          "name" : "[tomcat-dev] 20200213 svn commit: r1873980 [27/34] - /tomcat/site/trunk/docs/",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201705-09",
          "name" : "GLSA-201705-09",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20180531-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20180531-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.5:beta:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.26:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.27:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.28:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.29:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:8.0.30:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "LOW",
          "baseScore" : 6.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-02-25T01:59Z",
    "lastModifiedDate" : "2019-03-21T15:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0764",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "networkmanager",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-362"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2581.html",
          "name" : "RHSA-2016:2581",
          "refsource" : "REDHAT",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1324025",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1324025",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:redhat:networkmanager:*:*:*:*:*:*:*:*",
            "versionEndIncluding" : "1.0.8"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 2.1
        },
        "severity" : "LOW",
        "exploitabilityScore" : 3.9,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-07-17T13:18Z",
    "lastModifiedDate" : "2020-07-01T14:13Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0765",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "elfden",
            "product" : {
              "product_data" : [ {
                "product_name" : "eshop_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.openwall.com/lists/oss-security/2016/02/02/3",
          "name" : "[oss-security] 20160202 Reflected XSS & Blind SQLi in wordpress plugin eshop v6.3.14",
          "refsource" : "MLIST",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82347",
          "name" : "82347",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vapid.dhs.org/advisory.php?v=160",
          "name" : "http://www.vapid.dhs.org/advisory.php?v=160",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elfden:eshop_plugin:6.3.14:*:*:*:*:wordpress:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-01-23T21:59Z",
    "lastModifiedDate" : "2017-01-26T20:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0766",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1.19",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.html",
          "name" : "openSUSE-SU-2016:0531",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.html",
          "name" : "SUSE-SU-2016:0539",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.html",
          "name" : "SUSE-SU-2016:0555",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.html",
          "name" : "openSUSE-SU-2016:0578",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.html",
          "name" : "SUSE-SU-2016:0677",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3475",
          "name" : "DSA-3475",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3476",
          "name" : "DSA-3476",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/about/news/1644/",
          "name" : "http://www.postgresql.org/about/news/1644/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-1-20.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-1-20.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-2-15.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-2-15.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-3-11.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-3-11.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-4-6.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-4-6.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-5-1.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-5-1.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83184",
          "name" : "83184",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035005",
          "name" : "1035005",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2894-1",
          "name" : "USN-2894-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201701-33",
          "name" : "GLSA-201701-33",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.1.19"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-17T15:59Z",
    "lastModifiedDate" : "2017-07-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0767",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "tada_ab",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgre_sql_pl/java",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.4.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://tada.github.io/pljava/releasenotes.html",
          "name" : "https://tada.github.io/pljava/releasenotes.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:tada_ab:postgre_sql_pl\\/java:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.4.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-06-06T18:29Z",
    "lastModifiedDate" : "2017-06-13T18:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0768",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-284"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://tada.github.io/pljava/releasenotes.html",
          "name" : "https://tada.github.io/pljava/releasenotes.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL PL/Java after 9.0 does not honor access controls on large objects."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-06-06T18:29Z",
    "lastModifiedDate" : "2017-06-13T18:17Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0769",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "elfden",
            "product" : {
              "product_data" : [ {
                "product_name" : "eshop_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.3.14",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-89"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.openwall.com/lists/oss-security/2016/02/02/3",
          "name" : "[oss-security] 20160202 Reflected XSS & Blind SQLi in wordpress plugin eshop v6.3.14",
          "refsource" : "MLIST",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82347",
          "name" : "82347",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vapid.dhs.org/advisory.php?v=160",
          "name" : "http://www.vapid.dhs.org/advisory.php?v=160",
          "refsource" : "MISC",
          "tags" : [ "Exploit", "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:elfden:eshop_plugin:6.3.14:*:*:*:*:wordpress:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 6.5
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-01-23T21:59Z",
    "lastModifiedDate" : "2017-01-26T20:00Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0770",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "zahmit_design",
            "product" : {
              "product_data" : [ {
                "product_name" : "connections_business_directory_plugin",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "8.5.8",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.openwall.com/lists/oss-security/2016/02/02/1",
          "name" : "[oss-security] 20160201 Wordpress plugin Reflected XSS in connections v8.5.8",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82355",
          "name" : "82355",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.vapidlabs.com/advisory.php?v=161",
          "name" : "http://www.vapidlabs.com/advisory.php?v=161",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://wordpress.org/plugins/connections/changelog/",
          "name" : "https://wordpress.org/plugins/connections/changelog/",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:zahmit_design:connections_business_directory_plugin:*:*:*:*:*:wordpress:*:*",
          "versionEndIncluding" : "8.5.8"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-03-16T15:59Z",
    "lastModifiedDate" : "2017-03-17T12:26Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0771",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "samba",
            "product" : {
              "product_data" : [ {
                "product_name" : "samba",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00063.html",
          "name" : "openSUSE-SU-2016:0813",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3514",
          "name" : "DSA-3514",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/84273",
          "name" : "84273",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035219",
          "name" : "1035219",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2922-1",
          "name" : "USN-2922-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.samba.org/show_bug.cgi?id=11128",
          "name" : "https://bugzilla.samba.org/show_bug.cgi?id=11128",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.samba.org/show_bug.cgi?id=11686",
          "name" : "https://bugzilla.samba.org/show_bug.cgi?id=11686",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.samba.org/samba/security/CVE-2016-0771.html",
          "name" : "https://www.samba.org/samba/security/CVE-2016-0771.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.23:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.0.24:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.20:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.21:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.1.22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.0:rc3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.0:rc4:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.4.0:rc1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.4.0:rc2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:samba:samba:4.4.0:rc3:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 1.6,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:P/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 6.8,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-13T22:59Z",
    "lastModifiedDate" : "2016-12-03T03:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0772",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "python",
            "product" : {
              "product_data" : [ {
                "product_name" : "python",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.11",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.5.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-693"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html",
          "name" : "openSUSE-SU-2020:0086",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1626.html",
          "name" : "RHSA-2016:1626",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1627.html",
          "name" : "RHSA-2016:1627",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1628.html",
          "name" : "RHSA-2016:1628",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1629.html",
          "name" : "RHSA-2016:1629",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1630.html",
          "name" : "RHSA-2016:1630",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/06/14/9",
          "name" : "[oss-security] 20160614 Python CVE-2016-0772: smtplib StartTLS stripping attack",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91225",
          "name" : "91225",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.splunk.com/view/SP-CAAAPSV",
          "name" : "http://www.splunk.com/view/SP-CAAAPSV",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.splunk.com/view/SP-CAAAPUE",
          "name" : "http://www.splunk.com/view/SP-CAAAPUE",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1303647",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1303647",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5",
          "name" : "https://docs.python.org/3.4/whatsnew/changelog.html#python-3-4-5",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes" ]
        }, {
          "url" : "https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2",
          "name" : "https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-2",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes" ]
        }, {
          "url" : "https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWS",
          "name" : "https://hg.python.org/cpython/raw-file/v2.7.12/Misc/NEWS",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes" ]
        }, {
          "url" : "https://hg.python.org/cpython/rev/b3ce713fb9be",
          "name" : "https://hg.python.org/cpython/rev/b3ce713fb9be",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://hg.python.org/cpython/rev/d590114c2394",
          "name" : "https://hg.python.org/cpython/rev/d590114c2394",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        }, {
          "url" : "https://lists.debian.org/debian-lts-announce/2019/02/msg00011.html",
          "name" : "[debian-lts-announce] 20190207 [SECURITY] [DLA 1663-1] python3.4 security update",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201701-18",
          "name" : "GLSA-201701-18",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a \"StartTLS stripping attack.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.5.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.1.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.1.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.1.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.3.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:3.4.4:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.7.11"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.8
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 4.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-09-02T14:59Z",
    "lastModifiedDate" : "2019-02-09T11:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0773",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "postgresql",
            "product" : {
              "product_data" : [ {
                "product_name" : "postgresql",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1.19",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.2.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.4.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.5",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177820.html",
          "name" : "FEDORA-2016-e0a6c9ebc4",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177878.html",
          "name" : "FEDORA-2016-b0c2412ab2",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.html",
          "name" : "openSUSE-SU-2016:0531",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.html",
          "name" : "SUSE-SU-2016:0539",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.html",
          "name" : "SUSE-SU-2016:0555",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.html",
          "name" : "openSUSE-SU-2016:0578",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.html",
          "name" : "SUSE-SU-2016:0677",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1060.html",
          "name" : "RHSA-2016:1060",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3475",
          "name" : "DSA-3475",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3476",
          "name" : "DSA-3476",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/about/news/1644/",
          "name" : "http://www.postgresql.org/about/news/1644/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-1-20.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-1-20.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-2-15.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-2-15.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-3-11.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-3-11.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-4-6.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-4-6.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.postgresql.org/docs/current/static/release-9-5-1.html",
          "name" : "http://www.postgresql.org/docs/current/static/release-9-5-1.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83184",
          "name" : "83184",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035005",
          "name" : "1035005",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2894-1",
          "name" : "USN-2894-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10152",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10152",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://puppet.com/security/cve/CVE-2016-0773",
          "name" : "https://puppet.com/security/cve/CVE-2016-0773",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201701-33",
          "name" : "GLSA-201701-33",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.1.19"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.2.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-17T15:59Z",
    "lastModifiedDate" : "2017-12-09T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0774",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "linux",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux_kernel",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00025.html",
          "name" : "SUSE-SU-2016:1031",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00026.html",
          "name" : "SUSE-SU-2016:1032",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00027.html",
          "name" : "SUSE-SU-2016:1033",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00028.html",
          "name" : "SUSE-SU-2016:1034",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00029.html",
          "name" : "SUSE-SU-2016:1035",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00030.html",
          "name" : "SUSE-SU-2016:1037",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00031.html",
          "name" : "SUSE-SU-2016:1038",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00032.html",
          "name" : "SUSE-SU-2016:1039",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00033.html",
          "name" : "SUSE-SU-2016:1040",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00034.html",
          "name" : "SUSE-SU-2016:1041",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00036.html",
          "name" : "SUSE-SU-2016:1045",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00037.html",
          "name" : "SUSE-SU-2016:1046",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0494.html",
          "name" : "RHSA-2016:0494",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0617.html",
          "name" : "RHSA-2016:0617",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-05-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-05-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3503",
          "name" : "DSA-3503",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/84126",
          "name" : "84126",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2967-1",
          "name" : "USN-2967-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2967-2",
          "name" : "USN-2967-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2968-1",
          "name" : "USN-2968-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2968-2",
          "name" : "USN-2968-2",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1303961",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1303961",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security-tracker.debian.org/tracker/CVE-2016-0774",
          "name" : "https://security-tracker.debian.org/tracker/CVE-2016-0774",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an \"I/O vector array overrun.\" NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-1805."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "6.0.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.8,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 4.2
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:P/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 5.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 7.8,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-27T17:59Z",
    "lastModifiedDate" : "2016-12-03T03:18Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0775",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "python",
            "product" : {
              "product_data" : [ {
                "product_name" : "pillow",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://www.debian.org/security/2016/dsa-3499",
          "name" : "DSA-3499",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst",
          "name" : "https://github.com/python-pillow/Pillow/blob/c3cb690fed5d4bf0c45576759de55d054916c165/CHANGES.rst",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://github.com/python-pillow/Pillow/commit/893a40850c2d5da41537958e40569c029a6e127b",
          "name" : "https://github.com/python-pillow/Pillow/commit/893a40850c2d5da41537958e40569c029a6e127b",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201612-52",
          "name" : "GLSA-201612-52",
          "refsource" : "GENTOO",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-13T16:59Z",
    "lastModifiedDate" : "2017-07-01T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0776",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ ]
        } ]
      },
      "references" : {
        "reference_data" : [ ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ ]
    },
    "impact" : { },
    "publishedDate" : "2017-05-09T15:29Z",
    "lastModifiedDate" : "2017-05-09T15:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0777",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "remote_device_access_virtual_customer_access_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "15.07",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sophos",
            "product" : {
              "product_data" : [ {
                "product_name" : "unified_threat_management_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.318",
                    "version_affected" : "="
                  }, {
                    "version_value" : "9.353",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.11.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html",
          "name" : "APPLE-SA-2016-03-21-5",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.html",
          "name" : "FEDORA-2016-2e89eba0c1",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.html",
          "name" : "FEDORA-2016-67c6ef0d4f",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.html",
          "name" : "FEDORA-2016-c330264861",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.html",
          "name" : "FEDORA-2016-4556904561",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html",
          "name" : "SUSE-SU-2016:0117",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html",
          "name" : "SUSE-SU-2016:0118",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html",
          "name" : "SUSE-SU-2016:0119",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html",
          "name" : "SUSE-SU-2016:0120",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html",
          "name" : "openSUSE-SU-2016:0127",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html",
          "name" : "openSUSE-SU-2016:0128",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html",
          "name" : "http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Jan/44",
          "name" : "20160115 Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3446",
          "name" : "DSA-3446",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.openssh.com/txt/release-7.1p2",
          "name" : "http://www.openssh.com/txt/release-7.1p2",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/14/7",
          "name" : "[oss-security] 20160114 Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778",
          "refsource" : "MLIST",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537295/100/0/threaded",
          "name" : "20160114 Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/80695",
          "name" : "80695",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034671",
          "name" : "1034671",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2869-1",
          "name" : "USN-2869-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/",
          "name" : "https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/",
          "name" : "https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa109",
          "name" : "https://bto.bluecoat.com/security-advisory/sa109",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:07.openssh.asc",
          "name" : "FreeBSD-SA-16:07",
          "refsource" : "FREEBSD",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201601-01",
          "name" : "GLSA-201601-01",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://support.apple.com/HT206167",
          "name" : "https://support.apple.com/HT206167",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:sophos:unified_threat_management_software:9.318:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:sophos:unified_threat_management_software:9.353:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:110:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:120:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:220:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:320:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:425:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:525:*:*:*:*:*:*:*"
          }, {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:h:sophos:unified_threat_management:625:*:*:*:*:*:*:*"
          } ]
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.0:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.1:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.2:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.3:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.4:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.5:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.6:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.7:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.8:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.9:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.0:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.1:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.2:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.2:p2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.3:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.4:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.5:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.6:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.7:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.8:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.9:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.0:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.1:p1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:hp:remote_device_access_virtual_customer_access_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "15.07"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.11.3"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-14T22:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0778",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openbsd",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssh",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "sophos",
            "product" : {
              "product_data" : [ {
                "product_name" : "unified_threat_management_software",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.353",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.9.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.9.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.9.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.9.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.10.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.10.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.10.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "10.11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "hp",
            "product" : {
              "product_data" : [ {
                "product_name" : "virtual_customer_access_system",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "15.07",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "oracle",
            "product" : {
              "product_data" : [ {
                "product_name" : "linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "solaris",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "11.3",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html",
          "name" : "APPLE-SA-2016-03-21-5",
          "refsource" : "APPLE",
          "tags" : [ "Mailing List", "Release Notes", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.html",
          "name" : "FEDORA-2016-2e89eba0c1",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.html",
          "name" : "FEDORA-2016-4556904561",
          "refsource" : "FEDORA",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html",
          "name" : "SUSE-SU-2016:0117",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html",
          "name" : "SUSE-SU-2016:0118",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html",
          "name" : "SUSE-SU-2016:0119",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html",
          "name" : "SUSE-SU-2016:0120",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html",
          "name" : "openSUSE-SU-2016:0127",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html",
          "name" : "openSUSE-SU-2016:0128",
          "refsource" : "SUSE",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html",
          "name" : "http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://seclists.org/fulldisclosure/2016/Jan/44",
          "name" : "20160115 Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778",
          "refsource" : "FULLDISC",
          "tags" : [ "Mailing List", "Third Party Advisory" ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3446",
          "name" : "DSA-3446",
          "refsource" : "DEBIAN",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.openssh.com/txt/release-7.1p2",
          "name" : "http://www.openssh.com/txt/release-7.1p2",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Release Notes", "Vendor Advisory" ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/01/14/7",
          "name" : "[oss-security] 20160114 Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778",
          "refsource" : "MLIST",
          "tags" : [ "Exploit", "Mailing List", "Technical Description", "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537295/100/0/threaded",
          "name" : "20160114 Qualys Security Advisory - Roaming through the OpenSSH client: CVE-2016-0777 and CVE-2016-0778",
          "refsource" : "BUGTRAQ",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/80698",
          "name" : "80698",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1034671",
          "name" : "1034671",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2869-1",
          "name" : "USN-2869-1",
          "refsource" : "UBUNTU",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/",
          "name" : "https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes", "Vendor Advisory" ]
        }, {
          "url" : "https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/",
          "name" : "https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/",
          "refsource" : "CONFIRM",
          "tags" : [ "Release Notes", "Vendor Advisory" ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa109",
          "name" : "https://bto.bluecoat.com/security-advisory/sa109",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "refsource" : "CONFIRM",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201601-01",
          "name" : "GLSA-201601-01",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://support.apple.com/HT206167",
          "name" : "https://support.apple.com/HT206167",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.4:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.5:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.6:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.7:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.8:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.9:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.0:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.1:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.2:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.2:p2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.3:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.4:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.5:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.6:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.7:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.8:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:6.9:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.0:p1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:7.1:p1:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.9.0",
          "versionEndIncluding" : "10.9.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.10.0",
          "versionEndIncluding" : "10.10.5"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "10.11.0",
          "versionEndIncluding" : "10.11.3"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:hp:virtual_customer_access_system:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "15.07"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:sophos:unified_threat_management_software:9.353:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.1,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:H/Au:S/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "HIGH",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 4.6
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.4,
        "acInsufInfo" : false,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-01-14T22:59Z",
    "lastModifiedDate" : "2019-12-27T16:08Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0779",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "tomee",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.7.3",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "7.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-502"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/136256/Apache-TomEE-Patched.html",
          "name" : "http://packetstormsecurity.com/files/136256/Apache-TomEE-Patched.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://tomee.apache.org/security/tomee.html",
          "name" : "http://tomee.apache.org/security/tomee.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://tomee-openejb.979440.n4.nabble.com/Document-resolved-vulnerability-CVE-2015-8581-td4678073.html",
          "name" : "[tomee-dev] 20160404 Document resolved vulnerability CVE-2015-8581",
          "refsource" : "MLIST",
          "tags" : [ "Issue Tracking" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537806/100/0/threaded",
          "name" : "20160315 [ANNOUNCE][CVE-2016-0779] Apache TomEE 1.7.4 and 7.0.0-M3 releases",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/79204",
          "name" : "79204",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.zerodayinitiative.com/advisories/ZDI-15-638",
          "name" : "http://www.zerodayinitiative.com/advisories/ZDI-15-638",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomee:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.7.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:tomee:7.0.0:m1:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-04-11T16:59Z",
    "lastModifiedDate" : "2018-10-09T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0780",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pivotal_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_foundry_elastic_runtime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.5.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.17",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cloud_foundry_elastic_runtime_cf_release",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "231",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://pivotal.io/security/cve-2016-0780",
          "name" : "https://pivotal.io/security/cve-2016-0780",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attacker could use an improper disk quota value to bypass enforcement and consume all the disk on DEAs/CELLs causing a potential denial of service for other applications."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.5.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime_cf_release:231:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "acInsufInfo" : true,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2017-05-25T17:29Z",
    "lastModifiedDate" : "2017-06-07T17:38Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0781",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "pivotal_software",
            "product" : {
              "product_data" : [ {
                "product_name" : "cloud_foundry",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "208",
                    "version_affected" : "="
                  }, {
                    "version_value" : "209",
                    "version_affected" : "="
                  }, {
                    "version_value" : "210",
                    "version_affected" : "="
                  }, {
                    "version_value" : "211",
                    "version_affected" : "="
                  }, {
                    "version_value" : "212",
                    "version_affected" : "="
                  }, {
                    "version_value" : "213",
                    "version_affected" : "="
                  }, {
                    "version_value" : "214",
                    "version_affected" : "="
                  }, {
                    "version_value" : "215",
                    "version_affected" : "="
                  }, {
                    "version_value" : "216",
                    "version_affected" : "="
                  }, {
                    "version_value" : "217",
                    "version_affected" : "="
                  }, {
                    "version_value" : "218",
                    "version_affected" : "="
                  }, {
                    "version_value" : "219",
                    "version_affected" : "="
                  }, {
                    "version_value" : "220",
                    "version_affected" : "="
                  }, {
                    "version_value" : "221",
                    "version_affected" : "="
                  }, {
                    "version_value" : "222",
                    "version_affected" : "="
                  }, {
                    "version_value" : "223",
                    "version_affected" : "="
                  }, {
                    "version_value" : "224",
                    "version_affected" : "="
                  }, {
                    "version_value" : "225",
                    "version_affected" : "="
                  }, {
                    "version_value" : "226",
                    "version_affected" : "="
                  }, {
                    "version_value" : "227",
                    "version_affected" : "="
                  }, {
                    "version_value" : "228",
                    "version_affected" : "="
                  }, {
                    "version_value" : "229",
                    "version_affected" : "="
                  }, {
                    "version_value" : "230",
                    "version_affected" : "="
                  }, {
                    "version_value" : "231",
                    "version_affected" : "="
                  }, {
                    "version_value" : "241",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cloud_foundry_elastic_runtime",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.18",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.6.19",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cloud_foundry_uaa",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.7.4.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "3.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3.2.0",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "cloud_foundry_uaa_release",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "7",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "login-server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "https://pivotal.io/security/cve-2016-0781",
          "name" : "https://pivotal.io/security/cve-2016-0781",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:208:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:209:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:210:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:211:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:212:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:213:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:214:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:215:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:216:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:217:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:218:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:219:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:220:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:221:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:222:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:223:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:224:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:225:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:226:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:227:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:228:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:229:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:230:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:231:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry:241:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.8:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.9:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.10:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.11:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.12:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.13:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.14:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.15:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.16:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.17:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.18:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.19:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.7.4.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.0.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa_release:2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa_release:3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa_release:4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa_release:5:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa_release:6:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:cloud_foundry_uaa_release:7:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pivotal_software:login-server:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2017-05-25T17:29Z",
    "lastModifiedDate" : "2017-06-07T17:59Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0782",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "activemq",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.2.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.3.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.8.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.9.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.10.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.11.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.12.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.13.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.13.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-79"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txt",
          "name" : "http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/136215/Apache-ActiveMQ-5.13.0-Cross-Site-Scripting.html",
          "name" : "http://packetstormsecurity.com/files/136215/Apache-ActiveMQ-5.13.0-Cross-Site-Scripting.html",
          "refsource" : "MISC",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537760/100/0/threaded",
          "name" : "20160310 [ANNOUNCE] CVE-2016-0782: ActiveMQ Web Console - Cross-Site Scripting",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035328",
          "name" : "1035328",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:1424",
          "name" : "RHSA-2016:1424",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1317516",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1317516",
          "refsource" : "CONFIRM",
          "tags" : [ "Issue Tracking", "Third Party Advisory" ]
        }, {
          "url" : "https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E",
          "name" : "[activemq-commits] 20190327 svn commit: r1042639 - in /websites/production/activemq/content/activemq-website: ./ projects/artemis/download/ projects/classic/download/ projects/cms/download/ security-advisories.data/",
          "refsource" : "MLIST",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.2.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.3.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.3.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.8.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.9.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.9.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.10.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.10.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.10.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.11.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.12.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.12.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.12.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.13.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:activemq:5.13.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.4,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.3,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 3.5
        },
        "severity" : "LOW",
        "exploitabilityScore" : 6.8,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-08-05T15:59Z",
    "lastModifiedDate" : "2019-03-27T20:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0783",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "openmeetings",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://haxx.ml/post/141655340521/all-your-meetings-are-belong-to-us-remote-code",
          "name" : "http://haxx.ml/post/141655340521/all-your-meetings-are-belong-to-us-remote-code",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://openmeetings.apache.org/security.html",
          "name" : "http://openmeetings.apache.org/security.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/136432/Apache-OpenMeetings-3.1.0-MD5-Hashing.html",
          "name" : "http://packetstormsecurity.com/files/136432/Apache-OpenMeetings-3.1.0-MD5-Hashing.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537886/100/0/threaded",
          "name" : "20160325 [CVE-2016-0783] Predictable password reset token",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://www.apache.org/dist/openmeetings/3.1.1/CHANGELOG",
          "name" : "https://www.apache.org/dist/openmeetings/3.1.1/CHANGELOG",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-11T14:59Z",
    "lastModifiedDate" : "2018-10-09T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0784",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "openmeetings",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-22"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://haxx.ml/post/141655340521/all-your-meetings-are-belong-to-us-remote-code",
          "name" : "http://haxx.ml/post/141655340521/all-your-meetings-are-belong-to-us-remote-code",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://openmeetings.apache.org/security.html",
          "name" : "http://openmeetings.apache.org/security.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "http://packetstormsecurity.com/files/136484/Apache-OpenMeetings-3.1.0-Path-Traversal.html",
          "name" : "http://packetstormsecurity.com/files/136484/Apache-OpenMeetings-3.1.0-Path-Traversal.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "http://www.openwall.com/lists/oss-security/2016/03/25/2",
          "name" : "[oss-security] 20160325 [CVE-2016-0784] ZIP file path traversal",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/archive/1/537929/100/0/threaded",
          "name" : "20160330 [CVE-2016-0784] Apache OpenMeetings ZIP file path traversal",
          "refsource" : "BUGTRAQ",
          "tags" : [ ]
        }, {
          "url" : "https://www.apache.org/dist/openmeetings/3.1.1/CHANGELOG",
          "name" : "https://www.apache.org/dist/openmeetings/3.1.1/CHANGELOG",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39642/",
          "name" : "39642",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "3.1.0"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.5,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-11T14:59Z",
    "lastModifiedDate" : "2018-10-09T19:58Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0785",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apache",
            "product" : {
              "product_data" : [ {
                "product_name" : "struts",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.0.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.11.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.0.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.1.8.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.5",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.6",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.7",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.8",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.9",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.10",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.11",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.12",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.13",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.14",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.14.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.14.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.14.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.15",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.15.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.15.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.15.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.16",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.16.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.16.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.16.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.17",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.19",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.20",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.20.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.20.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.21",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.23",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.24",
                    "version_affected" : "="
                  }, {
                    "version_value" : "2.3.24.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://struts.apache.org/docs/s2-029.html",
          "name" : "http://struts.apache.org/docs/s2-029.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.securityfocus.com/bid/85066",
          "name" : "85066",
          "refsource" : "BID",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035271",
          "name" : "1035271",
          "refsource" : "SECTRACK",
          "tags" : [ "Third Party Advisory", "VDB Entry" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a \"%{}\" sequence in a tag attribute, aka forced double OGNL evaluation."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.0.0",
          "versionEndExcluding" : "2.3.20.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*",
          "versionStartIncluding" : "2.3.21",
          "versionEndIncluding" : "2.3.24.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-12T16:59Z",
    "lastModifiedDate" : "2019-08-23T15:50Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0787",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libssh2",
            "product" : {
              "product_data" : [ {
                "product_name" : "libssh2",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.6.0",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "debian",
            "product" : {
              "product_data" : [ {
                "product_name" : "debian_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "7.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "8.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "fedoraproject",
            "product" : {
              "product_data" : [ {
                "product_name" : "fedora",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "22",
                    "version_affected" : "="
                  }, {
                    "version_value" : "23",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "opensuse",
            "product" : {
              "product_data" : [ {
                "product_name" : "opensuse",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "13.2",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177980.html",
          "name" : "FEDORA-2016-215a2219b1",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178573.html",
          "name" : "FEDORA-2016-7942ee2cc5",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-03/msg00008.html",
          "name" : "openSUSE-SU-2016:0639",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3487",
          "name" : "DSA-3487",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/82514",
          "name" : "82514",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "https://bto.bluecoat.com/security-advisory/sa120",
          "name" : "https://bto.bluecoat.com/security-advisory/sa120",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10156",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10156",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://puppet.com/security/cve/CVE-2016-0787",
          "name" : "https://puppet.com/security/cve/CVE-2016-0787",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201606-12",
          "name" : "GLSA-201606-12",
          "refsource" : "GENTOO",
          "tags" : [ "Third Party Advisory" ]
        }, {
          "url" : "https://www.libssh2.org/adv_20160223.html",
          "name" : "https://www.libssh2.org/adv_20160223.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.libssh2.org/CVE-2016-0787.patch",
          "name" : "https://www.libssh2.org/CVE-2016-0787.patch",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a \"bits/bytes confusion bug.\""
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.6.0"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-13T17:59Z",
    "lastModifiedDate" : "2018-10-30T16:27Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0788",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jenkins",
            "product" : {
              "product_data" : [ {
                "product_name" : "jenkins",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.642.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.649",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "openshift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1773.html",
          "name" : "RHSA-2016:1773",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:0711",
          "name" : "RHSA-2016:0711",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "name" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:1.642.1:*:*:*:lts:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.649"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-07T23:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0789",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jenkins",
            "product" : {
              "product_data" : [ {
                "product_name" : "jenkins",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.642.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.649",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "openshift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1773.html",
          "name" : "RHSA-2016:1773",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:0711",
          "name" : "RHSA-2016:0711",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "name" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
          "versionEndIncluding" : "1.642.1"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.649"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "CHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "LOW",
          "availabilityImpact" : "NONE",
          "baseScore" : 6.1,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 2.7
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-04-07T23:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0790",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jenkins",
            "product" : {
              "product_data" : [ {
                "product_name" : "jenkins",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.642.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.649",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "openshift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-254"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1773.html",
          "name" : "RHSA-2016:1773",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:0711",
          "name" : "RHSA-2016:0711",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "name" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
          "versionEndIncluding" : "1.642.1"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.649"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "LOW",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.3,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 1.4
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-07T23:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0791",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jenkins",
            "product" : {
              "product_data" : [ {
                "product_name" : "jenkins",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.642.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.649",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "openshift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1773.html",
          "name" : "RHSA-2016:1773",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:0711",
          "name" : "RHSA-2016:0711",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "name" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.649"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:1.642.1:*:*:*:lts:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "PARTIAL",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 7.5
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.4,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-07T23:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0792",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "jenkins",
            "product" : {
              "product_data" : [ {
                "product_name" : "jenkins",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.642.1",
                    "version_affected" : "<="
                  }, {
                    "version_value" : "1.649",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "openshift",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "3.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1773.html",
          "name" : "RHSA-2016:1773",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/errata/RHSA-2016:0711",
          "name" : "RHSA-2016:0711",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "name" : "https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24",
          "refsource" : "CONFIRM",
          "tags" : [ "Patch", "Vendor Advisory" ]
        }, {
          "url" : "https://www.contrastsecurity.com/security-influencers/serialization-must-die-act-2-xstream",
          "name" : "https://www.contrastsecurity.com/security-influencers/serialization-must-die-act-2-xstream",
          "refsource" : "MISC",
          "tags" : [ "Exploit" ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/42394/",
          "name" : "42394",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/43375/",
          "name" : "43375",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "1.649"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
          "versionEndIncluding" : "1.642.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "LOW",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "SINGLE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-04-07T23:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0793",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "redhat",
            "product" : {
              "product_data" : [ {
                "product_name" : "jboss_wildfly_application_server",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.0.0",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://packetstormsecurity.com/files/136323/Wildfly-Filter-Restriction-Bypass-Information-Disclosure.html",
          "name" : "http://packetstormsecurity.com/files/136323/Wildfly-Filter-Restriction-Bypass-Information-Disclosure.html",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1305937",
          "name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1305937",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20180215-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20180215-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03784en_us",
          "name" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03784en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39573/",
          "name" : "39573",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) \"meaningless\" characters."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "AND",
        "children" : [ {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : true,
            "cpe23Uri" : "cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:*:*:*:*:*:*:*"
          } ]
        }, {
          "operator" : "OR",
          "cpe_match" : [ {
            "vulnerable" : false,
            "cpe23Uri" : "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"
          } ]
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-04-01T19:59Z",
    "lastModifiedDate" : "2018-05-10T01:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0794",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libreoffice",
            "product" : {
              "product_data" : [ {
                "product_name" : "libreoffice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.3",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178036.html",
          "name" : "FEDORA-2016-962c0d156d",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-05/msg00110.html",
          "name" : "openSUSE-SU-2016:1415",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-07/msg00050.html",
          "name" : "openSUSE-SU-2016:1805",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2579.html",
          "name" : "RHSA-2016:2579",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3482",
          "name" : "DSA-3482",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035022",
          "name" : "1035022",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2899-1",
          "name" : "USN-2899-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.libreoffice.org/about-us/security/advisories/cve-2016-0794/",
          "name" : "https://www.libreoffice.org/about-us/security/advisories/cve-2016-0794/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1220",
          "name" : "20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro 'ReadRootData' Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1221",
          "name" : "20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro TabRack Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1222",
          "name" : "20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro Bullet Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.3"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-18T21:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0795",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "libreoffice",
            "product" : {
              "product_data" : [ {
                "product_name" : "libreoffice",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0.4",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "canonical",
            "product" : {
              "product_data" : [ {
                "product_name" : "ubuntu_linux",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "12.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "14.04",
                    "version_affected" : "="
                  }, {
                    "version_value" : "15.10",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178036.html",
          "name" : "FEDORA-2016-962c0d156d",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-05/msg00110.html",
          "name" : "openSUSE-SU-2016:1415",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-updates/2016-07/msg00050.html",
          "name" : "openSUSE-SU-2016:1805",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2579.html",
          "name" : "RHSA-2016:2579",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3482",
          "name" : "DSA-3482",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035022",
          "name" : "1035022",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2899-1",
          "name" : "USN-2899-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://www.libreoffice.org/about-us/security/advisories/cve-2016-0795/",
          "name" : "https://www.libreoffice.org/about-us/security/advisories/cve-2016-0795/",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1223",
          "name" : "20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro 'TocSuperLayout' Buffer Overflow Vulnerability",
          "refsource" : "IDEFENSE",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "5.0.4"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "REQUIRED",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 1.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 9.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 8.6,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : true
      }
    },
    "publishedDate" : "2016-02-18T21:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0797",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "NVD-CWE-Other"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html",
          "name" : "openSUSE-SU-2016:0627",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html",
          "name" : "openSUSE-SU-2016:0640",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html",
          "name" : "SUSE-SU-2016:0641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html",
          "name" : "SUSE-SU-2016:0678",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html",
          "name" : "openSUSE-SU-2016:0720",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html",
          "name" : "openSUSE-SU-2016:1239",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html",
          "name" : "openSUSE-SU-2016:1241",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html",
          "name" : "openSUSE-SU-2016:1566",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145889460330120&w=2",
          "name" : "HPSBGN03563",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2957.html",
          "name" : "RHSA-2016:2957",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3500",
          "name" : "DSA-3500",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83763",
          "name" : "83763",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2914-1",
          "name" : "USN-2914-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=c175308407858afff3fc8c2e5e085d94d12edc7d",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=c175308407858afff3fc8c2e5e085d94d12edc7d",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10156",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10156",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function, related to crypto/bn/bn.h and crypto/bn/bn_print.c."
        }, {
          "lang" : "en",
          "value" : "<a href=\"http://cwe.mitre.org/data/definitions/190.html\">CWE-190: Integer Overflow or Wraparound</a>\n<a href=\"http://cwe.mitre.org/data/definitions/476.html\">CWE-476: NULL Pointer Dereference</a>"
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "PARTIAL",
          "baseScore" : 5.0
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 10.0,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-03T20:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0798",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-399"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html",
          "name" : "openSUSE-SU-2016:0627",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3500",
          "name" : "DSA-3500",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83705",
          "name" : "83705",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2914-1",
          "name" : "USN-2914-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=259b664f950c2ba66fbf4b0fe5281327904ead21",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=259b664f950c2ba66fbf4b0fe5281327904ead21",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 7.5,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.8
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-03-03T20:59Z",
    "lastModifiedDate" : "2017-11-21T02:29Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0799",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "pulsesecure",
            "product" : {
              "product_data" : [ {
                "product_name" : "client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "steel_belted_radius",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178358.html",
          "name" : "FEDORA-2016-2802690366",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178817.html",
          "name" : "FEDORA-2016-e6807b3394",
          "refsource" : "FEDORA",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html",
          "name" : "openSUSE-SU-2016:0640",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html",
          "name" : "SUSE-SU-2016:0641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html",
          "name" : "SUSE-SU-2016:0678",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html",
          "name" : "openSUSE-SU-2016:0720",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html",
          "name" : "openSUSE-SU-2016:1239",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html",
          "name" : "openSUSE-SU-2016:1241",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145983526810210&w=2",
          "name" : "HPSBGN03569",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=146108058503441&w=2",
          "name" : "HPSBMU03575",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://openssl.org/news/secadv/20160301.txt",
          "name" : "http://openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0722.html",
          "name" : "RHSA-2016:0722",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-0996.html",
          "name" : "RHSA-2016:0996",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2073.html",
          "name" : "RHSA-2016:2073",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-2957.html",
          "name" : "RHSA-2016:2957",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.debian.org/security/2016/dsa-3500",
          "name" : "DSA-3500",
          "refsource" : "DEBIAN",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83755",
          "name" : "83755",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.ubuntu.com/usn/USN-2914-1",
          "name" : "USN-2914-1",
          "refsource" : "UBUNTU",
          "tags" : [ ]
        }, {
          "url" : "https://git.openssl.org/?p=openssl.git;a=commit;h=578b956fe741bf8e84055547b1e83c28dd902c73",
          "name" : "https://git.openssl.org/?p=openssl.git;a=commit;h=578b956fe741bf8e84055547b1e83c28dd902c73",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05126404",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05126404",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05135617",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05135617",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150736",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150736",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pulsesecure:client:-:*:*:*:*:android:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pulsesecure:client:-:*:*:*:*:iphone_os:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pulsesecure:steel_belted_radius:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-03-03T20:59Z",
    "lastModifiedDate" : "2018-01-05T02:30Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0800",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "openssl",
            "product" : {
              "product_data" : [ {
                "product_name" : "openssl",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "1.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1f",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1g",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1h",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1i",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1j",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1k",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1l",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1m",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1n",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1o",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1p",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1q",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.1r",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2a",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2b",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2c",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2d",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2e",
                    "version_affected" : "="
                  }, {
                    "version_value" : "1.0.2f",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "pulsesecure",
            "product" : {
              "product_data" : [ {
                "product_name" : "client",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              }, {
                "product_name" : "steel_belted_radius",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "-",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-310"
          }, {
            "lang" : "en",
            "value" : "CWE-200"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10722",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10722",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "name" : "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html",
          "name" : "SUSE-SU-2016:0617",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html",
          "name" : "SUSE-SU-2016:0620",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html",
          "name" : "SUSE-SU-2016:0621",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html",
          "name" : "SUSE-SU-2016:0624",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html",
          "name" : "openSUSE-SU-2016:0627",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html",
          "name" : "openSUSE-SU-2016:0628",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html",
          "name" : "SUSE-SU-2016:0631",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html",
          "name" : "openSUSE-SU-2016:0637",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html",
          "name" : "openSUSE-SU-2016:0638",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html",
          "name" : "openSUSE-SU-2016:0640",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html",
          "name" : "SUSE-SU-2016:0641",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html",
          "name" : "SUSE-SU-2016:0678",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html",
          "name" : "openSUSE-SU-2016:0720",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html",
          "name" : "SUSE-SU-2016:1057",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html",
          "name" : "openSUSE-SU-2016:1239",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html",
          "name" : "openSUSE-SU-2016:1241",
          "refsource" : "SUSE",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=145983526810210&w=2",
          "name" : "HPSBGN03569",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=146108058503441&w=2",
          "name" : "HPSBMU03575",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://marc.info/?l=bugtraq&m=146133665209436&w=2",
          "name" : "HPSBMU03573",
          "refsource" : "HP",
          "tags" : [ ]
        }, {
          "url" : "http://rhn.redhat.com/errata/RHSA-2016-1519.html",
          "name" : "RHSA-2016:1519",
          "refsource" : "REDHAT",
          "tags" : [ ]
        }, {
          "url" : "http://support.citrix.com/article/CTX208403",
          "name" : "http://support.citrix.com/article/CTX208403",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl",
          "name" : "20160302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016",
          "refsource" : "CISCO",
          "tags" : [ ]
        }, {
          "url" : "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160330-01-openssl-en",
          "name" : "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160330-01-openssl-en",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "name" : "http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
          "name" : "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/83733",
          "name" : "83733",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securityfocus.com/bid/91787",
          "name" : "91787",
          "refsource" : "BID",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035133",
          "name" : "1035133",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-623229.pdf",
          "name" : "http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-623229.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://access.redhat.com/security/vulnerabilities/drown",
          "name" : "https://access.redhat.com/security/vulnerabilities/drown",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-623229.pdf",
          "name" : "https://cert-portal.siemens.com/productcert/pdf/ssa-623229.pdf",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://drownattack.com",
          "name" : "https://drownattack.com",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03726en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03726en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "name" : "https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073516",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073516",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05096953",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05096953",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05143554",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05143554",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05176765",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05176765",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05307589",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05307589",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05386804",
          "name" : "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05386804",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes",
          "name" : "https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://ics-cert.us-cert.gov/advisories/ICSA-16-103-03",
          "name" : "https://ics-cert.us-cert.gov/advisories/ICSA-16-103-03",
          "refsource" : "MISC",
          "tags" : [ ]
        }, {
          "url" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "name" : "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10154",
          "name" : "https://kc.mcafee.com/corporate/index?page=content&id=SB10154",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc",
          "name" : "FreeBSD-SA-16:12",
          "refsource" : "FREEBSD",
          "tags" : [ ]
        }, {
          "url" : "https://security.gentoo.org/glsa/201603-15",
          "name" : "GLSA-201603-15",
          "refsource" : "GENTOO",
          "tags" : [ ]
        }, {
          "url" : "https://security.netapp.com/advisory/ntap-20160301-0001/",
          "name" : "https://security.netapp.com/advisory/ntap-20160301-0001/",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.kb.cert.org/vuls/id/583776",
          "name" : "VU#583776",
          "refsource" : "CERT-VN",
          "tags" : [ ]
        }, {
          "url" : "https://www.openssl.org/news/secadv/20160301.txt",
          "name" : "https://www.openssl.org/news/secadv/20160301.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a \"DROWN\" attack."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pulsesecure:client:-:*:*:*:*:iphone_os:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:pulsesecure:steel_belted_radius:-:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "attackVector" : "NETWORK",
          "attackComplexity" : "HIGH",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 5.9,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.2,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "accessVector" : "NETWORK",
          "accessComplexity" : "MEDIUM",
          "authentication" : "NONE",
          "confidentialityImpact" : "PARTIAL",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "NONE",
          "baseScore" : 4.3
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 8.6,
        "impactScore" : 2.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false,
        "userInteractionRequired" : false
      }
    },
    "publishedDate" : "2016-03-01T20:59Z",
    "lastModifiedDate" : "2018-11-30T21:31Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0801",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphone_os",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.11.3",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "tvos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "watchos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html",
          "name" : "APPLE-SA-2016-03-21-1",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html",
          "name" : "APPLE-SA-2016-03-21-2",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html",
          "name" : "APPLE-SA-2016-03-21-3",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html",
          "name" : "APPLE-SA-2016-03-21-5",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txt",
          "name" : "http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035353",
          "name" : "1035353",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://lists.debian.org/debian-lts-announce/2018/11/msg00015.html",
          "name" : "[debian-lts-announce] 20181113 [SECURITY] [DLA 1573-1] firmware-nonfree security update",
          "refsource" : "MLIST",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206166",
          "name" : "https://support.apple.com/HT206166",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206167",
          "name" : "https://support.apple.com/HT206167",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206168",
          "name" : "https://support.apple.com/HT206168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206169",
          "name" : "https://support.apple.com/HT206169",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://www.exploit-db.com/exploits/39801/",
          "name" : "39801",
          "refsource" : "EXPLOIT-DB",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.2.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.11.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.5,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2019-03-08T16:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0802",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "apple",
            "product" : {
              "product_data" : [ {
                "product_name" : "iphone_os",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.2.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "mac_os_x",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "10.11.3",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "tvos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "9.1",
                    "version_affected" : "<="
                  } ]
                }
              }, {
                "product_name" : "watchos",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "2.1",
                    "version_affected" : "<="
                  } ]
                }
              } ]
            }
          }, {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-20"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.html",
          "name" : "APPLE-SA-2016-03-21-1",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html",
          "name" : "APPLE-SA-2016-03-21-2",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00002.html",
          "name" : "APPLE-SA-2016-03-21-3",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html",
          "name" : "APPLE-SA-2016-03-21-5",
          "refsource" : "APPLE",
          "tags" : [ ]
        }, {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txt",
          "name" : "http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-004.txt",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "http://www.securitytracker.com/id/1035353",
          "name" : "1035353",
          "refsource" : "SECTRACK",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206166",
          "name" : "https://support.apple.com/HT206166",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206167",
          "name" : "https://support.apple.com/HT206167",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206168",
          "name" : "https://support.apple.com/HT206168",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://support.apple.com/HT206169",
          "name" : "https://support.apple.com/HT206169",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      }, {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.2.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "10.11.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "9.1"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
          "versionEndIncluding" : "2.1"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "ADJACENT_NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.8,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.8,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:A/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "ADJACENT_NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 8.3
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 6.5,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2019-03-08T16:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0803",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        }, {
          "url" : "https://android.googlesource.com/platform%2Fframeworks%2Fav/+/50270d98e26fa18b20ca88216c3526667b724ba7",
          "name" : "https://android.googlesource.com/platform%2Fframeworks%2Fav/+/50270d98e26fa18b20ca88216c3526667b724ba7",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation in the (1) SoftMPEG4Encoder or (2) SoftVPXEncoder component, aka internal bug 25812794."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2016-03-10T01:22Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0804",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-119"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://android.googlesource.com/platform%2Fframeworks%2Fav/+/224858e719d045c8554856b12c4ab73d2375cf33",
          "name" : "https://android.googlesource.com/platform%2Fframeworks%2Fav/+/224858e719d045c8554856b12c4ab73d2375cf33",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 improperly manages mDrmManagerClient objects, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25070434."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "NETWORK",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 9.8,
          "baseSeverity" : "CRITICAL"
        },
        "exploitabilityScore" : 3.9,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "NETWORK",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 10.0
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 10.0,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2016-03-14T14:48Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0805",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2016-03-11T15:10Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0806",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "4.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.0.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.1.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.2.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.3.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "4.4.3",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25344453."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.0.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.1.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.2.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.3.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2016-03-16T16:16Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0807",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://android.googlesource.com/platform%2Fsystem%2Fcore/+/d917514bd6b270df431ea4e781a865764d406120",
          "name" : "https://android.googlesource.com/platform%2Fsystem%2Fcore/+/d917514bd6b270df431ea4e781a865764d406120",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "HIGH",
          "integrityImpact" : "HIGH",
          "availabilityImpact" : "HIGH",
          "baseScore" : 8.4,
          "baseSeverity" : "HIGH"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 5.9
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "COMPLETE",
          "integrityImpact" : "COMPLETE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 7.2
        },
        "severity" : "HIGH",
        "exploitabilityScore" : 3.9,
        "impactScore" : 10.0,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2016-03-11T15:06Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0808",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "5.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.0.2",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "5.1.1",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-19"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://android.googlesource.com/platform/frameworks/minikin/+/ed4c8d79153baab7f26562afb8930652dfbf853b",
          "name" : "https://android.googlesource.com/platform/frameworks/minikin/+/ed4c8d79153baab7f26562afb8930652dfbf853b",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
          "lang" : "en",
          "value" : "Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298."
        } ]
      }
    },
    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*"
        } ]
      } ]
    },
    "impact" : {
      "baseMetricV3" : {
        "cvssV3" : {
          "version" : "3.0",
          "vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "attackVector" : "LOCAL",
          "attackComplexity" : "LOW",
          "privilegesRequired" : "NONE",
          "userInteraction" : "NONE",
          "scope" : "UNCHANGED",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "HIGH",
          "baseScore" : 6.2,
          "baseSeverity" : "MEDIUM"
        },
        "exploitabilityScore" : 2.5,
        "impactScore" : 3.6
      },
      "baseMetricV2" : {
        "cvssV2" : {
          "version" : "2.0",
          "vectorString" : "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "accessVector" : "LOCAL",
          "accessComplexity" : "LOW",
          "authentication" : "NONE",
          "confidentialityImpact" : "NONE",
          "integrityImpact" : "NONE",
          "availabilityImpact" : "COMPLETE",
          "baseScore" : 4.9
        },
        "severity" : "MEDIUM",
        "exploitabilityScore" : 3.9,
        "impactScore" : 6.9,
        "obtainAllPrivilege" : false,
        "obtainUserPrivilege" : false,
        "obtainOtherPrivilege" : false
      }
    },
    "publishedDate" : "2016-02-07T01:59Z",
    "lastModifiedDate" : "2016-03-14T15:28Z"
  }, {
    "cve" : {
      "data_type" : "CVE",
      "data_format" : "MITRE",
      "data_version" : "4.0",
      "CVE_data_meta" : {
        "ID" : "CVE-2016-0809",
        "ASSIGNER" : "cve@mitre.org"
      },
      "affects" : {
        "vendor" : {
          "vendor_data" : [ {
            "vendor_name" : "google",
            "product" : {
              "product_data" : [ {
                "product_name" : "android",
                "version" : {
                  "version_data" : [ {
                    "version_value" : "6.0",
                    "version_affected" : "="
                  }, {
                    "version_value" : "6.0.1",
                    "version_affected" : "="
                  } ]
                }
              } ]
            }
          } ]
        }
      },
      "problemtype" : {
        "problemtype_data" : [ {
          "description" : [ {
            "lang" : "en",
            "value" : "CWE-264"
          } ]
        } ]
      },
      "references" : {
        "reference_data" : [ {
          "url" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "name" : "http://source.android.com/security/bulletin/2016-02-01.html",
          "refsource" : "CONFIRM",
          "tags" : [ "Vendor Advisory" ]
        }, {
          "url" : "https://android.googlesource.com/platform/hardware/broadcom/wlan/+/2c5a4fac8bc8198f6a2635ede776f8de40a0c3e1",
          "name" : "https://android.googlesource.com/platform/hardware/broadcom/wlan/+/2c5a4fac8bc8198f6a2635ede776f8de40a0c3e1",
          "refsource" : "CONFIRM",
          "tags" : [ ]
        } ]
      },
      "description" : {
        "description_data" : [ {
       