First published: Tue Mar 04 2014(Updated: )
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =6.1.0.0 | |
IBM WebSphere Portal | =6.1.0.1 | |
IBM WebSphere Portal | =6.1.0.2 | |
IBM WebSphere Portal | =6.1.0.3 | |
IBM WebSphere Portal | =6.1.0.4 | |
IBM WebSphere Portal | =6.1.0.5 | |
IBM WebSphere Portal | =6.1.0.6 | |
IBM WebSphere Portal | =6.1.5.0 | |
IBM WebSphere Portal | =6.1.5.1 | |
IBM WebSphere Portal | =6.1.5.2 | |
IBM WebSphere Portal | =6.1.5.3 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
=6.1.0.0 | ||
=6.1.0.1 | ||
=6.1.0.2 | ||
=6.1.0.3 | ||
=6.1.0.4 | ||
=6.1.0.5 | ||
=6.1.0.6 | ||
=6.1.5.0 | ||
=6.1.5.1 | ||
=6.1.5.2 | ||
=6.1.5.3 | ||
=7.0.0.0 | ||
=7.0.0.1 | ||
=7.0.0.2 | ||
=8.0.0.0 | ||
=8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-6730 is classified as high due to its potential for unauthorized access to sensitive information.
To fix CVE-2013-6730, apply the relevant patches provided by IBM for your specific version of WebSphere Portal.
IBM WebSphere Portal versions 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10 are affected by CVE-2013-6730.
CVE-2013-6730 can be exploited by remote attackers to bypass intended read restrictions on specific items within the IBM WebSphere Portal.
Enabling the wcm.path.traversal.security setting does not fully protect against CVE-2013-6730, as it can still be bypassed by targeted attacks.