Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-33620", "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "state": "PUBLISHED", "assignerShortName": "jpcert", "dateReserved": "2024-05-22T00:23:59.245Z", "datePublished": "2024-06-18T05:44:53.121Z", "dateUpdated": "2024-08-13T19:17:23.562Z"}, "containers": {"cna": {"affected": [{"vendor": "Fsas Technologies Inc.", "product": "FUJITSU Business Application ID Link Manager II", "versions": [{"version": "V1.8 and earlier", "status": "affected"}]}, {"vendor": "Fsas Technologies Inc.", "product": "FUJITSU Software ID Link Manager", "versions": [{"version": "V2.0", "status": "affected"}]}, {"vendor": "Fsas Technologies Inc.", "product": "FUJITSU Software TIME CREATOR ID Link Manager", "versions": [{"version": "V2.3.0", "status": "affected"}, {"version": " V2.3.1", "status": "affected"}, {"version": " V2.4", "status": "affected"}, {"version": " V2.5", "status": "affected"}, {"version": " V2.6", "status": "affected"}, {"version": " and V2.7", "status": "affected"}]}, {"vendor": "Fsas Technologies Inc.", "product": "FUJITSU Software TIME CREATOR ID Link Manager", "versions": [{"version": "V3.0", "status": "affected"}, {"version": " V3.0.2", "status": "affected"}, {"version": " V3.0.2.1", "status": "affected"}, {"version": " and V3.0.3", "status": "affected"}]}], "descriptions": [{"lang": "en", "value": "Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker."}], "problemTypes": [{"descriptions": [{"description": "Absolute path traversal", "lang": "en", "type": "text"}]}], "references": [{"url": "https://www.fujitsu.com/jp/group/fsas/about/resources/security/2024/0617.html"}, {"url": "https://jvn.jp/en/jp/JVN65171386/"}], "providerMetadata": {"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce", "shortName": "jpcert", "dateUpdated": "2024-06-18T05:44:53.121Z"}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T02:36:04.361Z"}, "title": "CVE Program Container", "references": [{"url": "https://www.fujitsu.com/jp/group/fsas/about/resources/security/2024/0617.html", "tags": ["x_transferred"]}, {"url": "https://jvn.jp/en/jp/JVN65171386/", "tags": ["x_transferred"]}]}, {"problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-36", "lang": "en", "description": "CWE-36 Absolute Path Traversal"}]}], "affected": [{"vendor": "fujitsu", "product": "business_application_id_link_manager_ii", "cpes": ["cpe:2.3:a:fujitsu:business_application_id_link_manager_ii:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "0", "status": "affected", "lessThanOrEqual": "1.8", "versionType": "custom"}]}, {"vendor": "fujitsu", "product": "id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:id_link_manager:2.0:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.0", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:2.3.0:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.3.0", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:2.3.1:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.3.1", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:2.4:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.4", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:2.5:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.5", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:2.6:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.6", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:2.7:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.7", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:3.0:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "3.0", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:3.0.2:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "3.0.2", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:3.0.2.1:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "3.0.2.1", "status": "affected"}]}, {"vendor": "fujitsu", "product": "time_creator_id_link_manager", "cpes": ["cpe:2.3:a:fujitsu:time_creator_id_link_manager:3.0.3:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "3.0.3", "status": "affected"}]}], "metrics": [{"cvssV3_1": {"scope": "CHANGED", "version": "3.1", "baseScore": 8.6, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}}, {"other": {"type": "ssvc", "content": {"timestamp": "2024-08-12T17:27:20.527344Z", "id": "CVE-2024-33620", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-08-13T19:17:23.562Z"}}]}}