3.5
CVE-2013-5453
- EPSS 0.85%
- Veröffentlicht 13.11.2013 15:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Security Appscan Version 5.6.0.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 6.0.0.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 6.0.1.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 6.0.2.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 6.1.1.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.0.0.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.0.0.1 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.0.0.2 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.0.1.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.0.1.1 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.0.11 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.5.0.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.5.0.1 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.6.0.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.6.0.1 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.6.0.2 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.7.0.0 Update - Edition enterprise
Ibm ≫ Security Appscan Version 8.7.0.1 Update - Edition enterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.85% | 0.534 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www-01.ibm.com/support/docview.wss?uid=swg21655578
https://exchange.xforce.ibmcloud.com/vulnerabilities/88193