Lucene search

K
cveIbmCVE-2013-4006
HistoryNov 18, 2013 - 5:23 a.m.

CVE-2013-4006

2013-11-1805:23:57
CWE-310
ibm
web.nvd.nist.gov
39
ibm
websphere
application server
was
liberty profile
security
weak permissions
cve-2013-4006
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

41.3%

IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.

Affected configurations

Nvd
Node
ibmwebsphere_application_serverMatch8.5.0.0-liberty_profile
OR
ibmwebsphere_application_serverMatch8.5.0.1-liberty_profile
OR
ibmwebsphere_application_serverMatch8.5.0.2-liberty_profile
OR
ibmwebsphere_application_serverMatch8.5.5.0-liberty_profile
VendorProductVersionCPE
ibmwebsphere_application_server8.5.0.0cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:-:liberty_profile:*:*:*:*:*
ibmwebsphere_application_server8.5.0.1cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:-:liberty_profile:*:*:*:*:*
ibmwebsphere_application_server8.5.0.2cpe:2.3:a:ibm:websphere_application_server:8.5.0.2:-:liberty_profile:*:*:*:*:*
ibmwebsphere_application_server8.5.5.0cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:-:liberty_profile:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

41.3%

Related for CVE-2013-4006