VulnerabilityModified
CVE-2013-2993
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown…
MEDIUM 5.8EPSS 1.23%
Does this matter?
Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/websphere commerce
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR45302
- http://www-01.ibm.com/support/docview.wss?uid=swg21644391Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84031
- http://www-01.ibm.com/support/docview.wss?uid=swg1JR45302
- http://www-01.ibm.com/support/docview.wss?uid=swg21644391Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84031
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.