Lucene search

K
cveIbmCVE-2013-6719
HistoryMar 06, 2014 - 11:55 a.m.

CVE-2013-6719

2014-03-0611:55:05
CWE-78
ibm
web.nvd.nist.gov
43
cve-2013-6719
ibm tealeaf
cx
remote execution
authenticated users
shell metacharacters
web console
security vulnerability

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

9.2

Confidence

High

EPSS

0.632

Percentile

97.9%

delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.

Affected configurations

Nvd
Node
ibmtealeaf_cxMatch7.1
OR
ibmtealeaf_cxMatch7.2
OR
ibmtealeaf_cxMatch8.0
OR
ibmtealeaf_cxMatch8.1
OR
ibmtealeaf_cxMatch8.2
OR
ibmtealeaf_cxMatch8.3
OR
ibmtealeaf_cxMatch8.4
OR
ibmtealeaf_cxMatch8.5
OR
ibmtealeaf_cxMatch8.6
OR
ibmtealeaf_cxMatch8.7
OR
ibmtealeaf_cxMatch8.8
VendorProductVersionCPE
ibmtealeaf_cx7.1cpe:2.3:a:ibm:tealeaf_cx:7.1:*:*:*:*:*:*:*
ibmtealeaf_cx7.2cpe:2.3:a:ibm:tealeaf_cx:7.2:*:*:*:*:*:*:*
ibmtealeaf_cx8.0cpe:2.3:a:ibm:tealeaf_cx:8.0:*:*:*:*:*:*:*
ibmtealeaf_cx8.1cpe:2.3:a:ibm:tealeaf_cx:8.1:*:*:*:*:*:*:*
ibmtealeaf_cx8.2cpe:2.3:a:ibm:tealeaf_cx:8.2:*:*:*:*:*:*:*
ibmtealeaf_cx8.3cpe:2.3:a:ibm:tealeaf_cx:8.3:*:*:*:*:*:*:*
ibmtealeaf_cx8.4cpe:2.3:a:ibm:tealeaf_cx:8.4:*:*:*:*:*:*:*
ibmtealeaf_cx8.5cpe:2.3:a:ibm:tealeaf_cx:8.5:*:*:*:*:*:*:*
ibmtealeaf_cx8.6cpe:2.3:a:ibm:tealeaf_cx:8.6:*:*:*:*:*:*:*
ibmtealeaf_cx8.7cpe:2.3:a:ibm:tealeaf_cx:8.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

9.2

Confidence

High

EPSS

0.632

Percentile

97.9%