Lucene search

K
cveIbmCVE-2013-6316
HistoryDec 22, 2013 - 3:16 p.m.

CVE-2013-6316

2013-12-2215:16:04
CWE-264
ibm
web.nvd.nist.gov
19
cve-2013-6316
ibm websphere portal
content-selection
taxonomy component
remote attackers
sensitive information
wcm context processor
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

71.4%

IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-selection changes during Taxonomy component rendering, which allows remote attackers to obtain sensitive property information in opportunistic circumstances by leveraging an error in a Web Content Manager (WCM) context processor.

Affected configurations

Nvd
Node
ibmwebsphere_portalMatch7.0.0.0
OR
ibmwebsphere_portalMatch7.0.0.1
OR
ibmwebsphere_portalMatch7.0.0.2
OR
ibmwebsphere_portalMatch8.0.0.0
OR
ibmwebsphere_portalMatch8.0.0.1
VendorProductVersionCPE
ibmwebsphere_portal7.0.0.0cpe:2.3:a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*
ibmwebsphere_portal7.0.0.1cpe:2.3:a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*
ibmwebsphere_portal7.0.0.2cpe:2.3:a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*
ibmwebsphere_portal8.0.0.0cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*
ibmwebsphere_portal8.0.0.1cpe:2.3:a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

71.4%

Related for CVE-2013-6316