Lucene search

K
cveIbmCVE-2013-5452
HistoryDec 19, 2013 - 10:55 p.m.

CVE-2013-5452

2013-12-1922:55:04
CWE-200
ibm
web.nvd.nist.gov
17
ibm
filenet
business process framework
4.1.0
xxe
security
vulnerability
cve-2013-5452
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

44.2%

IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected configurations

Nvd
Node
ibmfilenet_business_process_frameworkMatch4.1.0
VendorProductVersionCPE
ibmfilenet_business_process_framework4.1.0cpe:2.3:a:ibm:filenet_business_process_framework:4.1.0:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

44.2%

Related for CVE-2013-5452