CVE-2013-0543
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote…
Does this matter?
Lower severity and a low EPSS score (2.53%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.53% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?&uid=swg21632423Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM75582Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82759VDB Entry, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?&uid=swg21632423Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM75582Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82759VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.