CVE-2013-4012: Medium severity IBM WebSphere Portal vulnerability
IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4012?
CVE-2013-4012 is classified as a medium severity vulnerability due to the potential for data modification and denial of service.
How do I fix CVE-2013-4012?
To fix CVE-2013-4012, upgrade your IBM WebSphere Portal to version 8.0.0.1 or later.
Who is affected by CVE-2013-4012?
CVE-2013-4012 affects users of IBM WebSphere Portal 8.0.0.0 and 8.0.0.1 when using Content Template Catalog 4.0.
What does CVE-2013-4012 allow attackers to do?
CVE-2013-4012 allows remote authenticated users to install Portal Application Archive files without administrative privileges, leading to potential data manipulation.
Is there a workaround for CVE-2013-4012?
There are no documented workarounds for CVE-2013-4012, so upgrading to the patched version is necessary.