Lucene search

K
nvd[email protected]NVD:CVE-2013-0520
HistoryMay 10, 2013 - 11:42 a.m.

CVE-2013-0520

2013-05-1011:42:29
CWE-20
web.nvd.nist.gov
3

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

33.1%

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data.

Affected configurations

Nvd
Node
ibmsterling_secure_proxyMatch3.2.0.0
OR
ibmsterling_secure_proxyMatch3.3.0.1
OR
ibmsterling_secure_proxyMatch3.4.0.0
OR
ibmsterling_secure_proxyMatch3.4.1.0
OR
ibmsterling_secure_proxyMatch3.4.1.2
OR
ibmsterling_secure_proxyMatch3.4.1.5
OR
ibmsterling_secure_proxyMatch3.4.1.6
VendorProductVersionCPE
ibmsterling_secure_proxy3.2.0.0cpe:2.3:a:ibm:sterling_secure_proxy:3.2.0.0:*:*:*:*:*:*:*
ibmsterling_secure_proxy3.3.0.1cpe:2.3:a:ibm:sterling_secure_proxy:3.3.0.1:*:*:*:*:*:*:*
ibmsterling_secure_proxy3.4.0.0cpe:2.3:a:ibm:sterling_secure_proxy:3.4.0.0:*:*:*:*:*:*:*
ibmsterling_secure_proxy3.4.1.0cpe:2.3:a:ibm:sterling_secure_proxy:3.4.1.0:*:*:*:*:*:*:*
ibmsterling_secure_proxy3.4.1.2cpe:2.3:a:ibm:sterling_secure_proxy:3.4.1.2:*:*:*:*:*:*:*
ibmsterling_secure_proxy3.4.1.5cpe:2.3:a:ibm:sterling_secure_proxy:3.4.1.5:*:*:*:*:*:*:*
ibmsterling_secure_proxy3.4.1.6cpe:2.3:a:ibm:sterling_secure_proxy:3.4.1.6:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

33.1%

Related for NVD:CVE-2013-0520