| Vulnerability Name: | CVE-2013-5397 (CCN-87293) | ||||||||
| Assigned: | 2013-12-13 | ||||||||
| Published: | 2013-12-13 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398. | ||||||||
| CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:N/A:N) 2.4 Low (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.4 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-5397 Source: CCN Type: SA56074 IBM Rational Focal Point Webservice Axis Gateway Two Vulnerabilities Source: CCN Type: IBM Security Bulletin 1654471 Webservice Axis Gateway vulnerability in Rational Focal Point (CVE-2013-5397, CVE-2013-5398) Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21654471 Source: CCN Type: BID-64338 IBM Rational Focal Point Webservice Axis Gateway CVE-2013-5397 Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-rational-cve20135397-info-disc(87293) Source: XF Type: UNKNOWN ibm-rational-cve20135397-info-disc(87293) Source: CCN Type: ZDI-13-284 IBM Rational Focal Point LoginController Servlet Information Disclosure Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||