CVE-2013-6734
low
CVSS v3
—
CVSS v2
3.5
VIR risk
3.5
Description
IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21664641
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | websphere_extreme_scale_client | {"endIncluding":"8.6.0.4"} | |
| ibm | websphere_extreme_scale_client | 7.0.0.0 | |
| ibm | websphere_extreme_scale_client | 7.1.0.0 | |
| ibm | websphere_extreme_scale_client | 7.1.0.2 | |
| ibm | websphere_extreme_scale_client | 7.1.0.3 | |
| ibm | websphere_extreme_scale_client | 7.1.1.0 | |
| ibm | websphere_extreme_scale_client | 7.1.1.1 | |
| ibm | websphere_extreme_scale_client | 8.5.0.0 | |
| ibm | websphere_extreme_scale_client | 8.5.0.1 | |
| ibm | websphere_extreme_scale_client | 8.5.0.2 | |
| ibm | websphere_extreme_scale_client | 8.5.0.3 | |
| ibm | websphere_extreme_scale_client | 8.6.0.0 | |
| ibm | websphere_extreme_scale_client | 8.6.0.1 | |
| ibm | websphere_extreme_scale_client | 8.6.0.2 | |
| ibm | websphere_extreme_scale_client | 8.6.0.3 | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341
- http://www-01.ibm.com/support/docview.wss?uid=swg21664641
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89397
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341
- http://www-01.ibm.com/support/docview.wss?uid=swg21664641
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89397
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.