IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-03-04 14:55
Updated : 2017-08-28 18:34
NVD link : CVE-2013-6730
Mitre link : CVE-2013-6730
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- websphere_portal