CVE-2013-4053

medium
Published 2013-09-20 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21647522

Application impact

VendorProductVersionsFixed
ibm ibmwebsphere_application_server8.5.0.0
ibm ibmwebsphere_application_server8.5.0.1
ibm ibmwebsphere_application_server8.5.0.2
ibm ibmwebsphere_application_server8.5.5.0
ibm ibmwebsphere_application_server7.0
ibm ibmwebsphere_application_server7.0.0.1
ibm ibmwebsphere_application_server7.0.0.2
ibm ibmwebsphere_application_server7.0.0.3
ibm ibmwebsphere_application_server7.0.0.4
ibm ibmwebsphere_application_server7.0.0.5
ibm ibmwebsphere_application_server7.0.0.6
ibm ibmwebsphere_application_server7.0.0.7
ibm ibmwebsphere_application_server7.0.0.8
ibm ibmwebsphere_application_server7.0.0.9
ibm ibmwebsphere_application_server7.0.0.10
ibm ibmwebsphere_application_server7.0.0.11
ibm ibmwebsphere_application_server7.0.0.12
ibm ibmwebsphere_application_server7.0.0.13
ibm ibmwebsphere_application_server7.0.0.14
ibm ibmwebsphere_application_server7.0.0.15
ibm ibmwebsphere_application_server7.0.0.16
ibm ibmwebsphere_application_server7.0.0.17
ibm ibmwebsphere_application_server7.0.0.18
ibm ibmwebsphere_application_server7.0.0.19
ibm ibmwebsphere_application_server7.0.0.21
ibm ibmwebsphere_application_server7.0.0.22
ibm ibmwebsphere_application_server7.0.0.23
ibm ibmwebsphere_application_server7.0.0.24
ibm ibmwebsphere_application_server7.0.0.25
ibm ibmwebsphere_application_server7.0.0.27
ibm ibmwebsphere_application_server7.0.0.29
ibm ibmwebsphere_application_server8.0.0.0
ibm ibmwebsphere_application_server8.0.0.1
ibm ibmwebsphere_application_server8.0.0.2
ibm ibmwebsphere_application_server8.0.0.3
ibm ibmwebsphere_application_server8.0.0.4
ibm ibmwebsphere_application_server8.0.0.5
ibm ibmwebsphere_application_server8.0.0.6
ibm ibmwebsphere_application_server8.0.0.7
ibm ibmwebsphere_application_server6.1
ibm ibmwebsphere_application_server6.1.0
ibm ibmwebsphere_application_server6.1.0.0
ibm ibmwebsphere_application_server6.1.0.1
ibm ibmwebsphere_application_server6.1.0.2
ibm ibmwebsphere_application_server6.1.0.3
ibm ibmwebsphere_application_server6.1.0.5
ibm ibmwebsphere_application_server6.1.0.7
ibm ibmwebsphere_application_server6.1.0.9
ibm ibmwebsphere_application_server6.1.0.11
ibm ibmwebsphere_application_server6.1.0.12
ibm ibmwebsphere_application_server6.1.0.13
ibm ibmwebsphere_application_server6.1.0.14
ibm ibmwebsphere_application_server6.1.0.15
ibm ibmwebsphere_application_server6.1.0.17
ibm ibmwebsphere_application_server6.1.0.19
ibm ibmwebsphere_application_server6.1.0.21
ibm ibmwebsphere_application_server6.1.0.23
ibm ibmwebsphere_application_server6.1.0.25
ibm ibmwebsphere_application_server6.1.0.27
ibm ibmwebsphere_application_server6.1.0.29
ibm ibmwebsphere_application_server6.1.0.31
ibm ibmwebsphere_application_server6.1.0.33
ibm ibmwebsphere_application_server6.1.0.35
ibm ibmwebsphere_application_server6.1.0.37
ibm ibmwebsphere_application_server6.1.0.39
ibm ibmwebsphere_application_server6.1.0.41
ibm ibmwebsphere_application_server6.1.0.43
ibm ibmwebsphere_application_server6.1.0.45
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.11
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.13
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.15
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.17
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.19
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.21
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.23
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.25
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.27
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.29
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.31
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.33
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.35
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.37
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.39
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.41
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.43
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.45
ibm ibmwebsphere_application_server_feature_pack_for_web_services6.1.0.47

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.