First published: Sun Dec 22 2013(Updated: )
IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM Content Template Catalog | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4012 is classified as a medium severity vulnerability due to the potential for data modification and denial of service.
To fix CVE-2013-4012, upgrade your IBM WebSphere Portal to version 8.0.0.1 or later.
CVE-2013-4012 affects users of IBM WebSphere Portal 8.0.0.0 and 8.0.0.1 when using Content Template Catalog 4.0.
CVE-2013-4012 allows remote authenticated users to install Portal Application Archive files without administrative privileges, leading to potential data manipulation.
There are no documented workarounds for CVE-2013-4012, so upgrading to the patched version is necessary.