CVE-2013-6735
CVE-2013-6735
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://osvdb.org/101255http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.htmlhttp://secunia.com/advisories/56161https://exchange.xforce.ibmcloud.com/vulnerabilities/89591https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777http://www-01.ibm.com/support/docview.wss?uid=swg21660289http://www.securityfocus.com/archive/1/530552/100/0/threadedhttp://www.securityfocus.com/bid/64496http://www.securitytracker.com/id/1029539