CVE-2013-0543

medium
Published 2013-04-24 · Modified 2026-04-29
CVSS v3
VIR risk
6.8

Description

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
linux linux-kernel-not-affected

Application impact

VendorProductVersionsFixed
ibm ibmwebsphere_application_server6.1.0.0
ibm ibmwebsphere_application_server6.1.0.1
ibm ibmwebsphere_application_server6.1.0.2
ibm ibmwebsphere_application_server6.1.0.3
ibm ibmwebsphere_application_server6.1.0.5
ibm ibmwebsphere_application_server6.1.0.7
ibm ibmwebsphere_application_server6.1.0.9
ibm ibmwebsphere_application_server6.1.0.11
ibm ibmwebsphere_application_server6.1.0.12
ibm ibmwebsphere_application_server6.1.0.13
ibm ibmwebsphere_application_server6.1.0.14
ibm ibmwebsphere_application_server6.1.0.15
ibm ibmwebsphere_application_server6.1.0.17
ibm ibmwebsphere_application_server6.1.0.19
ibm ibmwebsphere_application_server6.1.0.21
ibm ibmwebsphere_application_server6.1.0.23
ibm ibmwebsphere_application_server6.1.0.25
ibm ibmwebsphere_application_server6.1.0.27
ibm ibmwebsphere_application_server6.1.0.29
ibm ibmwebsphere_application_server6.1.0.31
ibm ibmwebsphere_application_server6.1.0.33
ibm ibmwebsphere_application_server6.1.0.35
ibm ibmwebsphere_application_server6.1.0.37
ibm ibmwebsphere_application_server6.1.0.39
ibm ibmwebsphere_application_server6.1.0.41
ibm ibmwebsphere_application_server6.1.0.43
ibm ibmwebsphere_application_server6.1.0.45
ibm ibmwebsphere_application_server7.0.0.1
ibm ibmwebsphere_application_server7.0.0.2
ibm ibmwebsphere_application_server7.0.0.3
ibm ibmwebsphere_application_server7.0.0.4
ibm ibmwebsphere_application_server7.0.0.5
ibm ibmwebsphere_application_server7.0.0.6
ibm ibmwebsphere_application_server7.0.0.7
ibm ibmwebsphere_application_server7.0.0.8
ibm ibmwebsphere_application_server7.0.0.9
ibm ibmwebsphere_application_server7.0.0.11
ibm ibmwebsphere_application_server7.0.0.13
ibm ibmwebsphere_application_server7.0.0.15
ibm ibmwebsphere_application_server7.0.0.17
ibm ibmwebsphere_application_server7.0.0.19
ibm ibmwebsphere_application_server7.0.0.21
ibm ibmwebsphere_application_server7.0.0.23
ibm ibmwebsphere_application_server7.0.0.25
ibm ibmwebsphere_application_server7.0.0.27
ibm ibmwebsphere_application_server8.0.0.0
ibm ibmwebsphere_application_server8.0.0.1
ibm ibmwebsphere_application_server8.0.0.2
ibm ibmwebsphere_application_server8.0.0.3
ibm ibmwebsphere_application_server8.0.0.4
ibm ibmwebsphere_application_server8.0.0.5
ibm ibmwebsphere_application_server8.5.0.0
ibm ibmwebsphere_application_server8.5.0.1

References

CWEs

CWE-863

💬 Discuss CVE-2013-0543 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.