CVE-2023-38751 Vulnerability Details

  /     /     /  

CVE-2023-38751 Metadata Quick Info

CVE Published: 09/08/2023 | CVE Updated: 17/10/2024 | CVE Year: 2023
Source: jpcert | Vendor: Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) | Product: Special Interest Group Network for Analysis and Liaison
Status : PUBLISHED

CVE-2023-38751 Description

Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization information of the information receiver that is set as "non-disclosure" in the information provision operation.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper authorization
Source: Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).