ID

VAR-201903-1269


CVE

CVE-2019-0741


TITLE

Azure IoT Java SDK Vulnerability in which information is disclosed

Trust: 0.8

sources: JVNDB: JVNDB-2019-002330

DESCRIPTION

An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'. A remote attacker could use this vulnerability to obtain information

Trust: 2.52

sources: NVD: CVE-2019-0741 // JVNDB: JVNDB-2019-002330 // CNNVD: CNNVD-201902-409 // BID: 106971 // VULMON: CVE-2019-0741

AFFECTED PRODUCTS

vendor:microsoftmodel:java software development kitscope:eqversion: -

Trust: 1.0

vendor:microsoftmodel:java sdkscope:eqversion:for azure iot

Trust: 0.8

vendor:microsoftmodel:java sdk for azure iotscope:eqversion:0

Trust: 0.3

sources: BID: 106971 // JVNDB: JVNDB-2019-002330 // NVD: CVE-2019-0741

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-0741
value: HIGH

Trust: 1.0

NVD: CVE-2019-0741
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201902-409
value: HIGH

Trust: 0.6

VULMON: CVE-2019-0741
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-0741
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2019-0741
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULMON: CVE-2019-0741 // JVNDB: JVNDB-2019-002330 // CNNVD: CNNVD-201902-409 // NVD: CVE-2019-0741

PROBLEMTYPE DATA

problemtype:CWE-532

Trust: 1.8

sources: JVNDB: JVNDB-2019-002330 // NVD: CVE-2019-0741

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201902-409

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201902-409

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-002330

PATCH

title:CVE-2019-0741 | Azure IoT Java SDK Information Disclosure Vulnerability\url:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0741

Trust: 0.8

title:CVE-2019-0741 | Azure IoT Java SDK の情報漏えいの脆弱性url:https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/CVE-2019-0741

Trust: 0.8

title:Microsoft Azure IoT Java SDK Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89223

Trust: 0.6

title:Description Content Install Usage Automation Examplesurl:https://github.com/eeenvik1/scripts_for_YouTrack

Trust: 0.1

sources: VULMON: CVE-2019-0741 // JVNDB: JVNDB-2019-002330 // CNNVD: CNNVD-201902-409

EXTERNAL IDS

db:NVDid:CVE-2019-0741

Trust: 2.8

db:BIDid:106971

Trust: 1.9

db:JVNDBid:JVNDB-2019-002330

Trust: 0.8

db:CNNVDid:CNNVD-201902-409

Trust: 0.6

db:VULMONid:CVE-2019-0741

Trust: 0.1

sources: VULMON: CVE-2019-0741 // BID: 106971 // JVNDB: JVNDB-2019-002330 // CNNVD: CNNVD-201902-409 // NVD: CVE-2019-0741

REFERENCES

url:https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/cve-2019-0741

Trust: 1.9

url:http://www.securityfocus.com/bid/106971

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-0741

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-0741

Trust: 0.8

url:https://www.ipa.go.jp/security/ciadr/vul/20190213-ms.html

Trust: 0.8

url:http://www.jpcert.or.jp/at/2019/at190006.html

Trust: 0.8

url:http://www.microsoft.com

Trust: 0.3

sources: BID: 106971 // JVNDB: JVNDB-2019-002330 // CNNVD: CNNVD-201902-409 // NVD: CVE-2019-0741

CREDITS

Microsoft

Trust: 0.9

sources: BID: 106971 // CNNVD: CNNVD-201902-409

SOURCES

db:VULMONid:CVE-2019-0741
db:BIDid:106971
db:JVNDBid:JVNDB-2019-002330
db:CNNVDid:CNNVD-201902-409
db:NVDid:CVE-2019-0741

LAST UPDATE DATE

2024-11-23T21:52:22.989000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2019-0741date:2019-03-08T00:00:00
db:BIDid:106971date:2019-02-12T00:00:00
db:JVNDBid:JVNDB-2019-002330date:2019-04-05T00:00:00
db:CNNVDid:CNNVD-201902-409date:2019-04-01T00:00:00
db:NVDid:CVE-2019-0741date:2024-11-21T04:17:12.230

SOURCES RELEASE DATE

db:VULMONid:CVE-2019-0741date:2019-03-05T00:00:00
db:BIDid:106971date:2019-02-12T00:00:00
db:JVNDBid:JVNDB-2019-002330date:2019-04-05T00:00:00
db:CNNVDid:CNNVD-201902-409date:2019-02-12T00:00:00
db:NVDid:CVE-2019-0741date:2019-03-05T23:29:02.770