5
CVSSv2

CVE-2013-6735

Published: 22/12/2013 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM WebSphere Portal 6.0.0.x up to and including 6.0.0.1, 6.0.1.x up to and including 6.0.1.7, 6.1.0.x up to and including 6.1.0.6 CF27, 6.1.5.x up to and including 6.1.5.3 CF27, 7.0.0.x up to and including 7.0.0.2 CF26, and 8.0.0.x up to and including 8.0.0.1 CF08 allows remote malicious users to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere portal 7.0.0.1

ibm websphere portal 7.0.0.2

ibm websphere portal 6.1.0.2

ibm websphere portal 6.1.0.3

ibm websphere portal 6.1.0.4

ibm websphere portal 6.0.1.4

ibm websphere portal 6.0.1.5

ibm websphere portal 6.1.5.0

ibm websphere portal 6.1.5.1

ibm websphere portal 6.1.0.5

ibm websphere portal 6.1.0.6

ibm websphere portal 6.0.1.6

ibm websphere portal 6.0.1.7

ibm websphere portal 8.0.0.1

ibm websphere portal 6.1.5.2

ibm websphere portal 6.1.5.3

ibm websphere portal 6.0.1.0

ibm websphere portal 6.0.1.1

ibm websphere portal 6.0.0.1

ibm websphere portal 6.0.0.0

ibm websphere portal 8.0.0.0

ibm websphere portal 7.0.0.0

ibm websphere portal 6.1.0.0

ibm websphere portal 6.1.0.1

ibm websphere portal 6.0.1.2

ibm websphere portal 6.0.1.3

Exploits

IBM Web Content Manager versions 6x, 7x, and 8x suffer from blind XPath injection attacks This allows an attacker to get current application configuration, enumerate nodes, and extract other valuable information from vulnerable installations of Web Content Manager ...