7.2
CVSSv2

CVE-2013-3709

Published: 23/12/2013 Updated: 14/01/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse webyast 1.3

suse studio onsite 1.3

novell suse lifecycle management server 1.3