VulnerabilityModified
CVE-2013-6728
The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging incorrect security constraints for a temporary directory.
MEDIUM 5.8EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging incorrect security constraints for a temporary directory.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere dashboard framework
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO78265
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO78266
- http://www-01.ibm.com/support/docview.wss?uid=swg21663022Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89283
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO78265
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO78266
- http://www-01.ibm.com/support/docview.wss?uid=swg21663022Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89283
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.