IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21660289 | Patch Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777 | Not Applicable |
http://www.securitytracker.com/id/1029539 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/64496 | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.html | Exploit Third Party Advisory VDB Entry |
http://secunia.com/advisories/56161 | |
https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735 | Third Party Advisory VDB Entry |
http://osvdb.org/101255 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89591 | |
http://www.securityfocus.com/archive/1/530552/100/0/threaded |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-12-22 07:16
Updated : 2018-10-09 12:34
NVD link : CVE-2013-6735
Mitre link : CVE-2013-6735
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- websphere_portal