CVE-2013-2993

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_commerce:6.0.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:6.0.0.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ibm:websphere_commerce:7.0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_commerce:7.0.0.6:*:*:*:*:*:*:*

Information

Published : 2013-08-01 06:32

Updated : 2017-08-28 18:33


NVD link : CVE-2013-2993

Mitre link : CVE-2013-2993


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

ibm

  • websphere_commerce