CVE-2013-6735
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content…
Does this matter?
Lower severity and a low EPSS score (3.60%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.60% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere portal
- Source
- psirt@us.ibm.com
References
- http://osvdb.org/101255
- http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/56161
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg21660289Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/530552/100/0/threaded
- http://www.securityfocus.com/bid/64496Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029539Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89591
- https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735Third Party Advisory, VDB Entry
- http://osvdb.org/101255
- http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/56161
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg21660289Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/530552/100/0/threaded
- http://www.securityfocus.com/bid/64496Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029539Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89591
- https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.