3.5
CVE-2013-5414
- EPSS 0.16%
- Veröffentlicht 18.11.2013 05:23:57
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Application Server Version7.0
Ibm ≫ Websphere Application Server Version7.0.0.1
Ibm ≫ Websphere Application Server Version7.0.0.2
Ibm ≫ Websphere Application Server Version7.0.0.3
Ibm ≫ Websphere Application Server Version7.0.0.4
Ibm ≫ Websphere Application Server Version7.0.0.5
Ibm ≫ Websphere Application Server Version7.0.0.6
Ibm ≫ Websphere Application Server Version7.0.0.7
Ibm ≫ Websphere Application Server Version7.0.0.8
Ibm ≫ Websphere Application Server Version7.0.0.9
Ibm ≫ Websphere Application Server Version7.0.0.10
Ibm ≫ Websphere Application Server Version7.0.0.11
Ibm ≫ Websphere Application Server Version7.0.0.12
Ibm ≫ Websphere Application Server Version7.0.0.13
Ibm ≫ Websphere Application Server Version7.0.0.14
Ibm ≫ Websphere Application Server Version7.0.0.15
Ibm ≫ Websphere Application Server Version7.0.0.16
Ibm ≫ Websphere Application Server Version7.0.0.17
Ibm ≫ Websphere Application Server Version7.0.0.18
Ibm ≫ Websphere Application Server Version7.0.0.19
Ibm ≫ Websphere Application Server Version7.0.0.21
Ibm ≫ Websphere Application Server Version7.0.0.22
Ibm ≫ Websphere Application Server Version7.0.0.23
Ibm ≫ Websphere Application Server Version7.0.0.24
Ibm ≫ Websphere Application Server Version7.0.0.25
Ibm ≫ Websphere Application Server Version7.0.0.27
Ibm ≫ Websphere Application Server Version7.0.0.29
Ibm ≫ Websphere Application Server Version8.0.0.0
Ibm ≫ Websphere Application Server Version8.0.0.1
Ibm ≫ Websphere Application Server Version8.0.0.2
Ibm ≫ Websphere Application Server Version8.0.0.3
Ibm ≫ Websphere Application Server Version8.0.0.4
Ibm ≫ Websphere Application Server Version8.0.0.5
Ibm ≫ Websphere Application Server Version8.0.0.6
Ibm ≫ Websphere Application Server Version8.0.0.7
Ibm ≫ Websphere Application Server Version8.5.0.0
Ibm ≫ Websphere Application Server Version8.5.0.1
Ibm ≫ Websphere Application Server Version8.5.0.2
Ibm ≫ Websphere Application Server Version8.5.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.334 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|