First published: Sun Dec 22 2013(Updated: )
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =6.0.0.0 | |
IBM WebSphere Portal | =6.0.0.1 | |
IBM WebSphere Portal | =6.0.1.0 | |
IBM WebSphere Portal | =6.0.1.1 | |
IBM WebSphere Portal | =6.0.1.2 | |
IBM WebSphere Portal | =6.0.1.3 | |
IBM WebSphere Portal | =6.0.1.4 | |
IBM WebSphere Portal | =6.0.1.5 | |
IBM WebSphere Portal | =6.0.1.6 | |
IBM WebSphere Portal | =6.0.1.7 | |
IBM WebSphere Portal | =6.1.0.0 | |
IBM WebSphere Portal | =6.1.0.1 | |
IBM WebSphere Portal | =6.1.0.2 | |
IBM WebSphere Portal | =6.1.0.3 | |
IBM WebSphere Portal | =6.1.0.4 | |
IBM WebSphere Portal | =6.1.0.5 | |
IBM WebSphere Portal | =6.1.0.6 | |
IBM WebSphere Portal | =6.1.5.0 | |
IBM WebSphere Portal | =6.1.5.1 | |
IBM WebSphere Portal | =6.1.5.2 | |
IBM WebSphere Portal | =6.1.5.3 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6735 has a medium severity score due to the potential for remote attackers to access sensitive information.
To fix CVE-2013-6735, you should apply the latest security patches provided by IBM for your version of WebSphere Portal.
CVE-2013-6735 affects IBM WebSphere Portal versions 6.0.0.x through 8.0.0.1.
The risks of CVE-2013-6735 include unauthorized access to sensitive Java Content Repository information.
A potential workaround for CVE-2013-6735 is to restrict access to the affected components to trusted users only.