Vulnerability Name: CVE-2013-0513 (CCN-82594) Assigned: 2012-12-16 Published: 2013-03-25 Updated: 2017-08-29 Summary: IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program, related to an "Unquoted Service Path Enumeration" vulnerability. CVSS v3 Severity: 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2013-0513 Source: CCN Type: SA52764IBM Security AppScan Enterprise Multiple Vulnerabilities Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21626264 Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21631304 Source: CCN Type: IBM Security Bulletin 1626264Multiple vulnerabilities in IBM Security AppScan Enterprise (CVE-2013-0532, CVE-2013-0510, CVE-2013-0512, CVE-2012-4431, CVE-2013-0513, CVE-2008-4033, CVE-2013-0474, CVE-2013-0511, CVE-2013-0473, CVE-2012-5081) Source: CCN Type: IBM Security Bulletin 1987846 (Rational ClearCase)Unquoted Service Path Enumeration vulnerability in IBM Rational ClearCase (CVE-2013-0513) Source: CCN Type: IBM Security Bulletin 1990130 (Rational ClearQuest)Unquoted Service Path Enumeration vulnerability in IBM Rational ClearQuest (CVE-2013-0513) Source: CCN Type: BID-58691Multiple IBM Products CVE-2013-0513 Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWNappscan-svc-path-priv-esc(82594) Source: XF Type: UNKNOWNappscan-svc-path-priv-esc(82594) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:security_appscan:5.6.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.0.2:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.1.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.1.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.0.11:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.5.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.5.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.0:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.1:-:enterprise:*:*:*:*:* OR cpe:/a:ibm:security_appscan:8.6.0.2:-:enterprise:*:*:*:*:* Configuration 2 :cpe:/a:ibm:rational_policy_tester:5.6.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_policy_tester:8.5.0.3:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:rational_appscan:5.2:*:enterprise:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:8.0.0:*:enterprise:*:*:*:*:* OR cpe:/a:ibm:rational_appscan:8.5.0:*:enterprise:*:*:*:*:* AND cpe:/a:ibm:rational_clearcase:7.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.8:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.8:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.10:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.11:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.8:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.1.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.10:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.11:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.12:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.8:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.12:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.8:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.13:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.14:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.10:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.2:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.13:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.10:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1.3:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.14:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1.4:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.12:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.12:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1.5:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:7.1.2.15:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.15:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:7.1.2.16:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.0.13:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:8.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.13:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.6:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.14:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.7:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.8:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.16:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.9:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.17:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.10:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.0.18:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:8.0.1.11:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:9.0:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearquest:9.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:rational_clearcase:9.0.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm security appscan 5.6.0.0 -
ibm security appscan 8.0.0.0 -
ibm security appscan 8.0.0.1 -
ibm security appscan 8.0.0.2 -
ibm security appscan 8.0.1.0 -
ibm security appscan 8.0.1.1 -
ibm security appscan 8.0.11 -
ibm security appscan 8.5.0.0 -
ibm security appscan 8.5.0.1 -
ibm security appscan 8.6.0.0 -
ibm security appscan 8.6.0.1 -
ibm security appscan 8.6.0.2 -
ibm rational policy tester 5.6.0.0
ibm rational policy tester 8.0.0.0
ibm rational policy tester 8.0.0.1
ibm rational policy tester 8.0.0.2
ibm rational policy tester 8.0.1.0
ibm rational policy tester 8.0.1.1
ibm rational policy tester 8.5.0.0
ibm rational policy tester 8.5.0.1
ibm rational policy tester 8.5.0.2
ibm rational policy tester 8.5.0.3
ibm rational appscan 5.2
ibm rational appscan 8.0.0
ibm rational appscan 8.5.0
ibm rational clearcase 7.1
ibm rational clearquest 7.1
ibm rational clearquest 7.1.0.2
ibm rational clearquest 7.1.1.3
ibm rational clearquest 7.1.1.2
ibm rational clearquest 7.1.1.1
ibm rational clearquest 7.1.2
ibm rational clearcase 7.1.0.1
ibm rational clearcase 7.1.0.2
ibm rational clearcase 7.1.1
ibm rational clearcase 7.1.1.1
ibm rational clearcase 7.1.1.2
ibm rational clearcase 7.1.1.3
ibm rational clearcase 7.1.1.4
ibm rational clearquest 7.1.0.1
ibm rational clearquest 7.1.1.4
ibm rational clearquest 8.0
ibm rational clearquest 7.1.1.5
ibm rational clearquest 7.1.1.6
ibm rational clearquest 7.1.1.7
ibm rational clearquest 7.1.1.8
ibm rational clearquest 7.1.2.1
ibm rational clearquest 7.1.2.2
ibm rational clearquest 7.1.2.3
ibm rational clearquest 7.1.2.4
ibm rational clearquest 7.1.2.5
ibm rational clearquest 8.0.0.1
ibm rational clearquest 7.1.2.6
ibm rational clearquest 7.1.2.7
ibm rational clearquest 7.1.2.8
ibm rational clearquest 8.0.0.2
ibm rational clearquest 8.0.0.3
ibm rational clearquest 8.0.0.4
ibm rational clearquest 7.1.2.9
ibm rational clearquest 8.0.0.5
ibm rational clearcase 8.0.0.3
ibm rational clearcase 8.0.0.4
ibm rational clearcase 8.0.0.5
ibm rational clearcase 8.0.0.6
ibm rational clearcase 8.0.0.7
ibm rational clearcase 8.0.1
ibm rational clearquest 7.1.1.9
ibm rational clearquest 7.1.2.10
ibm rational clearquest 7.1.2.11
ibm rational clearquest 8.0.0.6
ibm rational clearquest 8.0.0.7
ibm rational clearquest 8.0.1
ibm rational clearcase 7.1.1.5
ibm rational clearcase 7.1.1.6
ibm rational clearcase 7.1.1.7
ibm rational clearcase 7.1.1.8
ibm rational clearcase 7.1.1.9
ibm rational clearcase 7.1.2
ibm rational clearcase 7.1.2.1
ibm rational clearcase 7.1.2.2
ibm rational clearcase 7.1.2.3
ibm rational clearcase 7.1.2.4
ibm rational clearcase 7.1.2.5
ibm rational clearcase 7.1.2.6
ibm rational clearcase 7.1.2.7
ibm rational clearcase 7.1.2.9
ibm rational clearcase 7.1.2.10
ibm rational clearcase 7.1.2.11
ibm rational clearcase 7.1.2.12
ibm rational clearcase 8.0
ibm rational clearcase 8.0.0.1
ibm rational clearcase 8.0.0.2
ibm rational clearcase 8.0.0.8
ibm rational clearcase 8.0.1.1
ibm rational clearquest 7.1.1
ibm rational clearquest 7.1.2.12
ibm rational clearquest 8.0.0.8
ibm rational clearquest 8.0.1.1
ibm rational clearcase 8.0.1.2
ibm rational clearcase 8.0.0.9
ibm rational clearquest 7.1.2.13
ibm rational clearquest 7.1.2.14
ibm rational clearquest 8.0.0.9
ibm rational clearquest 8.0.0.10
ibm rational clearquest 8.0.0.11
ibm rational clearquest 8.0.1.2
ibm rational clearquest 8.0.1.3
ibm rational clearquest 8.0.1.4
ibm rational clearcase 7.1.2.13
ibm rational clearcase 8.0.0.10
ibm rational clearcase 8.0.1.3
ibm rational clearcase 7.1.2.14
ibm rational clearcase 8.0.0.11
ibm rational clearcase 8.0.1.4
ibm rational clearquest 8.0.0.12
ibm rational clearquest 8.0.1.5
ibm rational clearcase 8.0.0.12
ibm rational clearcase 8.0.1.5
ibm rational clearquest 7.1.2.15
ibm rational clearcase 7.1.2.15
ibm rational clearcase 7.1.2.16
ibm rational clearcase 8.0.0.13
ibm rational clearcase 8.0.1.6
ibm rational clearquest 8.0.0.13
ibm rational clearquest 8.0.1.6
ibm rational clearquest 8.0.0.14
ibm rational clearquest 8.0.1.7
ibm rational clearquest 8.0.0.15
ibm rational clearquest 8.0.1.8
ibm rational clearquest 8.0.0.16
ibm rational clearquest 8.0.1.9
ibm rational clearquest 8.0.0.17
ibm rational clearquest 8.0.1.10
ibm rational clearquest 8.0.0.18
ibm rational clearquest 8.0.1.11
ibm rational clearquest 9.0
ibm rational clearquest 9.0.0.1
ibm rational clearcase 9.0.1