CVE-2013-4006: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4006?
CVE-2013-4006 has a medium severity level due to the potential for local users to obtain sensitive information.
How do I fix CVE-2013-4006?
To fix CVE-2013-4006, ensure that proper permissions are set for sensitive files in IBM WebSphere Application Server Liberty Profile versions before 8.5.5.1.
Who is affected by CVE-2013-4006?
CVE-2013-4006 affects IBM WebSphere Application Server Liberty Profile versions 8.5.0.0, 8.5.0.1, 8.5.0.2, and 8.5.5.0.
What type of vulnerability is CVE-2013-4006?
CVE-2013-4006 is a local information disclosure vulnerability due to weak file permissions.
When was CVE-2013-4006 announced?
CVE-2013-4006 was announced in 2013 as part of IBM security advisories.