Lucene search

K
cve[email protected]CVE-2013-0600
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2013-0600

2022-10-0316:15:04
web.nvd.nist.gov
26
cve-2013-0600
ibm
websphere
datapower
xc10
appliance
vulnerability
bypass authentication
administrative actions
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.3%

Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and perform administrative actions via unknown vectors.

Affected configurations

NVD
Node
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.0.0.0
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.0.0.1
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.0.0.2
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.0.0.3
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.1.0.0
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.1.0.1
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.1.0.2
OR
ibmwebsphere_datapower_xc10_appliance_firmwareMatch2.1.0.3
AND
ibmwebsphere_datapower_xc10_applianceMatch-

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.3%

Related for CVE-2013-0600