Vulnerability Name:

CVE-2013-2962 (CCN-83722)

Assigned:2013-04-12
Published:2014-02-05
Updated:2017-08-29
Summary:Buffer overflow in the Launcher in IBM WebSphere Transformation Extender 8.4.x before 8.4.0.4 allows local users to cause a denial of service (process crash or Admin Console command-stream outage) via unspecified vectors.
CVSS v3 Severity:6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-2962

Source: CCN
Type: SA56751
IBM Tivoli Provisioning Manager Java Multiple Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 1662870
Multiple security vulnerabilities exist in WebSphere Transformation Extender (CVE-2013-5802 CVE-2013-4002 CVE-2013-5825 CVE-2013-5372 CVE-2013-0599 CVE-2013-0464 CVE-2013-0467 CVE-2013-2962 CVE-2013-2415)

Source: CONFIRM
Type: Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21662870

Source: CCN
Type: BID-65365
IBM WebSphere Transformation Extender CVE-2013-2962 Local Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
ibm-websphere-cve20132962-dos(83722)

Source: XF
Type: UNKNOWN
ibm-websphere-cve20132962-dos(83722)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_transformation_extender:8.4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_transformation_extender:8.3.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_transformation_extender:8.4.1.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere transformation extender 8.4.0.0
    ibm websphere transformation extender 8.4.0.1
    ibm websphere transformation extender 8.4.0.2
    ibm websphere transformation extender 8.4.0.3
    ibm websphere transformation extender 8.3.0.0
    ibm websphere transformation extender 8.4.0.0
    ibm websphere transformation extender 8.4.0.1
    ibm websphere transformation extender 8.4.0.2
    ibm websphere transformation extender 8.4.0.3
    ibm websphere transformation extender 8.4.0.4
    ibm websphere transformation extender 8.4.1.0
    ibm websphere transformation extender 8.4.1.1