CVE-2013-0482: Medium severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 through 8.5.0.2 and WebSphere Message Broker 6.1, 7.0 through 7.0.0.5, and 8.0 through 8.0.0.2, when WS-Security is used, allows remote attackers to spoof the signatures of messages via a crafted SOAP message, related to a "Signature Wrap attack," a different vulnerability than CVE-2011-1377 and CVE-2013-0489.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0482?
CVE-2013-0482 has a medium severity level as it allows remote attackers to spoof message signatures.
How do I fix CVE-2013-0482?
To fix CVE-2013-0482, update IBM WebSphere Application Server or WebSphere Message Broker to the latest versions provided by IBM.
Which versions are affected by CVE-2013-0482?
CVE-2013-0482 affects IBM WebSphere Application Server versions 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 up to 8.5.0.2, along with certain versions of WebSphere Message Broker.
What is the nature of the vulnerability in CVE-2013-0482?
The vulnerability in CVE-2013-0482 allows remote attackers to create crafted SOAP messages that can spoof message signatures.
Is CVE-2013-0482 critical for my infrastructure?
The criticality of CVE-2013-0482 depends on the deployment of the affected software and exposure to untrusted sources.