{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "nl",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n    NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n    NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n    This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            },
            {
                "category": "description",
                "text": "Oracle heeft kwetsbaarheden verholpen in Analytics producten.",
                "title": "Feiten"
            },
            {
                "category": "description",
                "text": "Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:\n\n- Denial-of-Service\n- Manipuleren van data\n- Uitvoer van willekeurige code (Gebruikersrechten)\n- Uitvoer van willekeurige code (Administratorrechten)\n- Toegang tot gevoelige gegevens",
                "title": "Interpretaties"
            },
            {
                "category": "description",
                "text": "Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.",
                "title": "Oplossingen"
            },
            {
                "category": "general",
                "text": "medium",
                "title": "Kans"
            },
            {
                "category": "general",
                "text": "high",
                "title": "Schade"
            },
            {
                "category": "general",
                "text": "Unchecked Input for Loop Condition",
                "title": "CWE-606"
            },
            {
                "category": "general",
                "text": "Improper Check for Unusual or Exceptional Conditions",
                "title": "CWE-754"
            },
            {
                "category": "general",
                "text": "Insufficient Verification of Data Authenticity",
                "title": "CWE-345"
            },
            {
                "category": "general",
                "text": "Missing Cryptographic Step",
                "title": "CWE-325"
            },
            {
                "category": "general",
                "text": "Improper Resource Shutdown or Release",
                "title": "CWE-404"
            },
            {
                "category": "general",
                "text": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
                "title": "CWE-119"
            },
            {
                "category": "general",
                "text": "Inefficient Regular Expression Complexity",
                "title": "CWE-1333"
            },
            {
                "category": "general",
                "text": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
                "title": "CWE-1321"
            },
            {
                "category": "general",
                "text": "NULL Pointer Dereference",
                "title": "CWE-476"
            },
            {
                "category": "general",
                "text": "Uncontrolled Resource Consumption",
                "title": "CWE-400"
            },
            {
                "category": "general",
                "text": "Allocation of Resources Without Limits or Throttling",
                "title": "CWE-770"
            },
            {
                "category": "general",
                "text": "Server-Side Request Forgery (SSRF)",
                "title": "CWE-918"
            },
            {
                "category": "general",
                "text": "Out-of-bounds Write",
                "title": "CWE-787"
            },
            {
                "category": "general",
                "text": "Heap-based Buffer Overflow",
                "title": "CWE-122"
            },
            {
                "category": "general",
                "text": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                "title": "CWE-89"
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "Nationaal Cyber Security Centrum",
            "namespace": "https://www.ncsc.nl/"
        },
        "references": [
            {
                "category": "external",
                "summary": "Reference - cveprojectv5; hkcert; nvd; oracle; redhat",
                "url": "https://www.oracle.com/security-alerts/cpuoct2024.html"
            }
        ],
        "title": "Kwetsbaarheden verholpen in Oracle Analytics",
        "tracking": {
            "current_release_date": "2024-10-17T13:19:50.583299Z",
            "id": "NCSC-2024-0418",
            "initial_release_date": "2024-10-17T13:19:50.583299Z",
            "revision_history": [
                {
                    "date": "2024-10-17T13:19:50.583299Z",
                    "number": "0",
                    "summary": "Initiele versie"
                }
            ],
            "status": "final",
            "version": "1.0.0"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-1503573",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_analytics_server___12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765388",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_analytics_server___5.9.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764727",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_analytics_server___6.4.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764729",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_analytics_server___7.0.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765383",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_bi_platform_security___12.2.1.3.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765385",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_bi_platform_security___12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765389",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_bi_platform_security___5.9.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764725",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_presentation_services___12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764728",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_presentation_services___6.4.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764730",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_presentation_services___7.0.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764726",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_service_administration_ui___12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765386",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:_storage_service_integration___12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765384",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:12.2.1.3.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764234",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-765387",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:5.5.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764929",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:5.9.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764778",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:5.9.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764930",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:6.4.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764235",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:6.4.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-764236",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:7.0.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence_enterprise_edition",
                        "product": {
                            "name": "business_intelligence_enterprise_edition",
                            "product_id": "CSAFPID-1503574",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence_enterprise_edition:7.6.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-376906",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:*:enterprise:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-135812",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-220360",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:*:enterprise:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-135810",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-179569",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-257324",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:7.0.0.0.0:*:*:*:enterprise:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "business_intelligence",
                        "product": {
                            "name": "business_intelligence",
                            "product_id": "CSAFPID-1650736",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:business_intelligence:7.6.0.0.0:*:*:*:enterprise:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-9197",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:12.2.1.3.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-9493",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-220546",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:5.9.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-228391",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:5.9.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-220545",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:6.4.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-220560",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:7.0.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    },
                    {
                        "category": "product_name",
                        "name": "bi_publisher",
                        "product": {
                            "name": "bi_publisher",
                            "product_id": "CSAFPID-1673195",
                            "product_identification_helper": {
                                "cpe": "cpe:2.3:a:oracle:bi_publisher:7.6.0.0.0:*:*:*:*:*:*:*"
                            }
                        }
                    }
                ],
                "category": "vendor",
                "name": "oracle"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2022-23305",
            "cwe": {
                "id": "CWE-89",
                "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
                    "title": "CWE-89"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-135810",
                    "CSAFPID-220545",
                    "CSAFPID-220560",
                    "CSAFPID-764725",
                    "CSAFPID-764726",
                    "CSAFPID-764234",
                    "CSAFPID-764727",
                    "CSAFPID-764728",
                    "CSAFPID-764235",
                    "CSAFPID-764729",
                    "CSAFPID-764730",
                    "CSAFPID-764236",
                    "CSAFPID-9493",
                    "CSAFPID-764778",
                    "CSAFPID-228391",
                    "CSAFPID-220546",
                    "CSAFPID-9197",
                    "CSAFPID-764929",
                    "CSAFPID-764930",
                    "CSAFPID-765383",
                    "CSAFPID-765384",
                    "CSAFPID-765385",
                    "CSAFPID-765386",
                    "CSAFPID-765387",
                    "CSAFPID-765388",
                    "CSAFPID-765389",
                    "CSAFPID-257324"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2022-23305",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2022/CVE-2022-23305.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-135810",
                        "CSAFPID-220545",
                        "CSAFPID-220560",
                        "CSAFPID-764725",
                        "CSAFPID-764726",
                        "CSAFPID-764234",
                        "CSAFPID-764727",
                        "CSAFPID-764728",
                        "CSAFPID-764235",
                        "CSAFPID-764729",
                        "CSAFPID-764730",
                        "CSAFPID-764236",
                        "CSAFPID-9493",
                        "CSAFPID-764778",
                        "CSAFPID-228391",
                        "CSAFPID-220546",
                        "CSAFPID-9197",
                        "CSAFPID-764929",
                        "CSAFPID-764930",
                        "CSAFPID-765383",
                        "CSAFPID-765384",
                        "CSAFPID-765385",
                        "CSAFPID-765386",
                        "CSAFPID-765387",
                        "CSAFPID-765388",
                        "CSAFPID-765389",
                        "CSAFPID-257324"
                    ]
                }
            ],
            "title": "CVE-2022-23305"
        },
        {
            "cve": "CVE-2023-0401",
            "cwe": {
                "id": "CWE-476",
                "name": "NULL Pointer Dereference"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "NULL Pointer Dereference",
                    "title": "CWE-476"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1650736",
                    "CSAFPID-135810",
                    "CSAFPID-220545",
                    "CSAFPID-220560",
                    "CSAFPID-764234",
                    "CSAFPID-764235",
                    "CSAFPID-764236",
                    "CSAFPID-764725",
                    "CSAFPID-764726",
                    "CSAFPID-764727",
                    "CSAFPID-764728",
                    "CSAFPID-764729",
                    "CSAFPID-764730"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2023-0401",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2023/CVE-2023-0401.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1650736",
                        "CSAFPID-135810",
                        "CSAFPID-220545",
                        "CSAFPID-220560",
                        "CSAFPID-764234",
                        "CSAFPID-764235",
                        "CSAFPID-764236",
                        "CSAFPID-764725",
                        "CSAFPID-764726",
                        "CSAFPID-764727",
                        "CSAFPID-764728",
                        "CSAFPID-764729",
                        "CSAFPID-764730"
                    ]
                }
            ],
            "title": "CVE-2023-0401"
        },
        {
            "cve": "CVE-2023-5678",
            "cwe": {
                "id": "CWE-754",
                "name": "Improper Check for Unusual or Exceptional Conditions"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improper Check for Unusual or Exceptional Conditions",
                    "title": "CWE-754"
                },
                {
                    "category": "other",
                    "text": "Missing Cryptographic Step",
                    "title": "CWE-325"
                },
                {
                    "category": "other",
                    "text": "Unchecked Input for Loop Condition",
                    "title": "CWE-606"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1650736",
                    "CSAFPID-257324",
                    "CSAFPID-9493",
                    "CSAFPID-220560",
                    "CSAFPID-764234",
                    "CSAFPID-764236",
                    "CSAFPID-1503573",
                    "CSAFPID-765385",
                    "CSAFPID-1503574"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2023-5678",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2023/CVE-2023-5678.json"
                }
            ],
            "title": "CVE-2023-5678"
        },
        {
            "cve": "CVE-2023-35116",
            "cwe": {
                "id": "CWE-770",
                "name": "Allocation of Resources Without Limits or Throttling"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Allocation of Resources Without Limits or Throttling",
                    "title": "CWE-770"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-9493",
                    "CSAFPID-257324",
                    "CSAFPID-220545",
                    "CSAFPID-220560",
                    "CSAFPID-764234",
                    "CSAFPID-764235",
                    "CSAFPID-764236",
                    "CSAFPID-1503573",
                    "CSAFPID-765385",
                    "CSAFPID-1503574"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2023-35116",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2023/CVE-2023-35116.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-9493",
                        "CSAFPID-257324",
                        "CSAFPID-220545",
                        "CSAFPID-220560",
                        "CSAFPID-764234",
                        "CSAFPID-764235",
                        "CSAFPID-764236",
                        "CSAFPID-1503573",
                        "CSAFPID-765385",
                        "CSAFPID-1503574"
                    ]
                }
            ],
            "title": "CVE-2023-35116"
        },
        {
            "cve": "CVE-2023-38545",
            "cwe": {
                "id": "CWE-122",
                "name": "Heap-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Heap-based Buffer Overflow",
                    "title": "CWE-122"
                },
                {
                    "category": "other",
                    "text": "Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "title": "CWE-119"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-9493",
                    "CSAFPID-220545",
                    "CSAFPID-220560",
                    "CSAFPID-764234",
                    "CSAFPID-764235",
                    "CSAFPID-764236",
                    "CSAFPID-1650736",
                    "CSAFPID-257324",
                    "CSAFPID-135810"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2023-38545",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2023/CVE-2023-38545.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-9493",
                        "CSAFPID-220545",
                        "CSAFPID-220560",
                        "CSAFPID-764234",
                        "CSAFPID-764235",
                        "CSAFPID-764236",
                        "CSAFPID-1650736",
                        "CSAFPID-257324",
                        "CSAFPID-135810"
                    ]
                }
            ],
            "title": "CVE-2023-38545"
        },
        {
            "cve": "CVE-2024-21195",
            "product_status": {
                "known_affected": [
                    "CSAFPID-9493",
                    "CSAFPID-1673195",
                    "CSAFPID-220560"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-21195",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-21195.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-9493",
                        "CSAFPID-1673195",
                        "CSAFPID-220560"
                    ]
                }
            ],
            "title": "CVE-2024-21195"
        },
        {
            "cve": "CVE-2024-21254",
            "product_status": {
                "known_affected": [
                    "CSAFPID-9493",
                    "CSAFPID-220560",
                    "CSAFPID-1673195"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-21254",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-21254.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-9493",
                        "CSAFPID-220560",
                        "CSAFPID-1673195"
                    ]
                }
            ],
            "title": "CVE-2024-21254"
        },
        {
            "cve": "CVE-2024-26308",
            "cwe": {
                "id": "CWE-770",
                "name": "Allocation of Resources Without Limits or Throttling"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Allocation of Resources Without Limits or Throttling",
                    "title": "CWE-770"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-257324",
                    "CSAFPID-9493",
                    "CSAFPID-220560",
                    "CSAFPID-764234",
                    "CSAFPID-764236",
                    "CSAFPID-1503573",
                    "CSAFPID-765385",
                    "CSAFPID-1503574"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-26308",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-26308.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-257324",
                        "CSAFPID-9493",
                        "CSAFPID-220560",
                        "CSAFPID-764234",
                        "CSAFPID-764236",
                        "CSAFPID-1503573",
                        "CSAFPID-765385",
                        "CSAFPID-1503574"
                    ]
                }
            ],
            "title": "CVE-2024-26308"
        },
        {
            "cve": "CVE-2024-29133",
            "cwe": {
                "id": "CWE-787",
                "name": "Out-of-bounds Write"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Out-of-bounds Write",
                    "title": "CWE-787"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-257324",
                    "CSAFPID-1503573",
                    "CSAFPID-765385",
                    "CSAFPID-764234",
                    "CSAFPID-764236",
                    "CSAFPID-1503574"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-29133",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-29133.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-257324",
                        "CSAFPID-1503573",
                        "CSAFPID-765385",
                        "CSAFPID-764234",
                        "CSAFPID-764236",
                        "CSAFPID-1503574"
                    ]
                }
            ],
            "title": "CVE-2024-29133"
        },
        {
            "cve": "CVE-2024-29736",
            "cwe": {
                "id": "CWE-918",
                "name": "Server-Side Request Forgery (SSRF)"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Server-Side Request Forgery (SSRF)",
                    "title": "CWE-918"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-220560",
                    "CSAFPID-1673195"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-29736",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-29736.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-220560",
                        "CSAFPID-1673195"
                    ]
                }
            ],
            "title": "CVE-2024-29736"
        },
        {
            "cve": "CVE-2024-38809",
            "cwe": {
                "id": "CWE-1333",
                "name": "Inefficient Regular Expression Complexity"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Inefficient Regular Expression Complexity",
                    "title": "CWE-1333"
                },
                {
                    "category": "other",
                    "text": "Improper Resource Shutdown or Release",
                    "title": "CWE-404"
                },
                {
                    "category": "other",
                    "text": "Uncontrolled Resource Consumption",
                    "title": "CWE-400"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-220560",
                    "CSAFPID-1673195"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-38809",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-38809.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.0",
                        "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-220560",
                        "CSAFPID-1673195"
                    ]
                }
            ],
            "title": "CVE-2024-38809"
        },
        {
            "cve": "CVE-2024-38999",
            "cwe": {
                "id": "CWE-1321",
                "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')",
                    "title": "CWE-1321"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-135810",
                    "CSAFPID-1650736",
                    "CSAFPID-257324"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-38999",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-38999.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-135810",
                        "CSAFPID-1650736",
                        "CSAFPID-257324"
                    ]
                }
            ],
            "title": "CVE-2024-38999"
        },
        {
            "cve": "CVE-2024-39689",
            "cwe": {
                "id": "CWE-345",
                "name": "Insufficient Verification of Data Authenticity"
            },
            "notes": [
                {
                    "category": "other",
                    "text": "Insufficient Verification of Data Authenticity",
                    "title": "CWE-345"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-1650736"
                ]
            },
            "references": [
                {
                    "category": "self",
                    "summary": "CVE-2024-39689",
                    "url": "https://api.ncsc.nl/velma/v1/vulnerabilities/2024/CVE-2024-39689.json"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-1650736"
                    ]
                }
            ],
            "title": "CVE-2024-39689"
        }
    ]
}