First published: Wed Dec 18 2013(Updated: )
Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Focal Point | =6.4 | |
IBM Rational Focal Point | =6.4.1.3 | |
IBM Rational Focal Point | =6.5.1 | |
IBM Rational Focal Point | =6.5.2 | |
IBM Rational Focal Point | =6.5.2.3 | |
IBM Rational Focal Point | =6.6 | |
IBM Rational Focal Point | =6.6.0.1 | |
IBM Rational Focal Point | =6.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-5398 is considered high due to the potential for unauthorized access by remote attackers.
Fix CVE-2013-5398 by applying the latest available devfix for your version of IBM Rational Focal Point.
CVE-2013-5398 affects IBM Rational Focal Point versions 6.4, 6.4.1.3, 6.5.1, 6.5.2, 6.5.2.3, 6.6, 6.6.0.1, and 6.6.1 before their respective devfix releases.
CVE-2013-5398 can be exploited by remote attackers to bypass intended access controls.
Currently, there are no official workarounds for CVE-2013-5398, and it is recommended to apply the necessary updates.