| Vulnerability Name: | CVE-2013-0540 (CCN-82695) | ||||||||
| Assigned: | 2012-12-16 | ||||||||
| Published: | 2013-04-15 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-0540 Source: CCN Type: IBM Security Bulletin 1632423 Security Vulnerabilites fixed in IBM WebSphere Application Server 8.5.0.2 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?&uid=swg21632423 Source: AIXAPAR Type: UNKNOWN PM81056 Source: XF Type: UNKNOWN was-ssl-sec-bypass(82695) Source: XF Type: UNKNOWN was-ssl-sec-bypass(82695) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||