CVE-2013-0652: Medium severity ge proficy real-time information portal vulnerability
GE Intelligent Platforms Proficy Real-Time Information Portal does not restrict access to methods of an unspecified Java class, which allows remote attackers to obtain a username listing via an RMI call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0652?
CVE-2013-0652 is classified as a high-severity vulnerability due to its potential for unauthorized access to user information.
How does CVE-2013-0652 affect GE Intelligent Platforms Proficy Real-Time Information Portal?
CVE-2013-0652 allows remote attackers to exploit unrestricted access to certain methods, potentially obtaining sensitive username listings.
How do I fix CVE-2013-0652?
To mitigate CVE-2013-0652, ensure that access controls are properly configured and updated to restrict method access.
Which versions of GE Intelligent Platforms Proficy Real-Time Information Portal are affected by CVE-2013-0652?
Versions 2.6, 3.0, 3.0-sp1, 3.5, and 3.5-sp1 of GE Intelligent Platforms Proficy Real-Time Information Portal are known to be affected by CVE-2013-0652.
What should I do if I am using an affected version of GE Intelligent Platforms Proficy Real-Time Information Portal and CVE-2013-0652 is present?
If using an affected version, it is recommended to apply any available security updates or patches to eliminate the vulnerability.