4.3
CVSSv2

CVE-2013-0523

Published: 21/06/2013 Updated: 30/09/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM WebSphere Commerce Enterprise 5.6.x up to and including 5.6.1.5, 6.0.x up to and including 6.0.0.11, and 7.0.x up to and including 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote malicious users to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere commerce 5.6.1.2

ibm websphere commerce 5.6.1.1

ibm websphere commerce 5.6.1.4

ibm websphere commerce 5.6.1.3

ibm websphere commerce 5.6.1.5

ibm websphere commerce 5.6.1

ibm websphere commerce 6.0.0.2

ibm websphere commerce 6.0.0.1

ibm websphere commerce 6.0.0.5

ibm websphere commerce 6.0.0.4

ibm websphere commerce 6.0.0.7

ibm websphere commerce 6.0.0.11

ibm websphere commerce 6.0.0.6

ibm websphere commerce 6.0.0.3

ibm websphere commerce 6.0.0.0

ibm websphere commerce 6.0.0.8

ibm websphere commerce 6.0.0.9

ibm websphere commerce 6.0.0.10

ibm websphere commerce 7.0.0.5

ibm websphere commerce 7.0.0.4

ibm websphere commerce 7.0.0.1

ibm websphere commerce 7.0

ibm websphere commerce 7.0.0.3

ibm websphere commerce 7.0.0.2

ibm websphere commerce 7.0.0.7

ibm websphere commerce 7.0.0.6