3.5
CVE-2013-2950
- EPSS 1.43%
- Veröffentlicht 03.06.2013 21:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Portal Version 8.0
Ibm ≫ Websphere Portal Version 8.0.0.0
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf01
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf02
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf03
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf04
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf05
Ibm ≫ Websphere Portal Version 8.0.0.1
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf04
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf05
Ibm ≫ Websphere Portal Version 7.0.0.0
Ibm ≫ Websphere Portal Version 7.0.0.0 Update cf001
Ibm ≫ Websphere Portal Version 7.0.0.1
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf002
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf003
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf004
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf005
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf006
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf007
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf008
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf009
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf010
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf019
Ibm ≫ Websphere Portal Version 7.0.0.2
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf011
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf012
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf013
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf014
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf015
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf016
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf017
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf018
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf019
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf020
Ibm ≫ Websphere Portal Version 6.1.0.0
Ibm ≫ Websphere Portal Version 6.1.0.1
Ibm ≫ Websphere Portal Version 6.1.0.2
Ibm ≫ Websphere Portal Version 6.1.0.3
Ibm ≫ Websphere Portal Version 6.1.5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.43% | 0.695 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
http://www-01.ibm.com/support/docview.wss?uid=swg1PM85071
http://www-01.ibm.com/support/docview.wss?uid=swg21638864
https://exchange.xforce.ibmcloud.com/vulnerabilities/83618