| |
Vulnerability CVE-2013-0505
Published: 2013-03-19
Description: |
IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors. |
Type:
CWE-200 (Information Exposure)
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5.5/10 |
4.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
None |
References: |
http://xforce.iss.net/xforce/xfdb/82339
http://www-01.ibm.com/support/docview.wss?uid=swg21631302
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|