{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-13T15:19:43.714","vulnerabilities":[{"cve":{"id":"CVE-2017-7435","sourceIdentifier":"security@opentext.com","published":"2018-03-01T20:29:00.617","lastModified":"2024-11-21T03:31:53.717","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system."},{"lang":"es","value":"En libzypp, en versiones anteriores a la 20170803, fue posible añadir repositorios YUM no firmados sin avisar al usuario. Esto podía resultar en que un atacante Man-in-the-Middle (MitM) o servidores maliciosos inyectasen paquetes RPM maliciosos en el sistema de un usuario."}],"metrics":{"cvssMetricV30":[{"source":"security@opentext.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opensuse:libzypp:*:*:*:*:*:*:*:*","versionEndIncluding":"16.15.2","matchCriteriaId":"4CAACEA3-7214-40A7-B212-DE6BED99F2C7"}]}]}],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1009127","source":"security@opentext.com"},{"url":"https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html","source":"security@opentext.com"},{"url":"https://www.suse.com/de-de/security/cve/CVE-2017-7435/","source":"security@opentext.com"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1009127","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.suse.com/de-de/security/cve/CVE-2017-7435/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}