« Volver al listado

CVE-2013-6734

Estado: ModificadaBaja (3.5)—

IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6734",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-02-22T21:55:09.170",
  "references": [
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21664641",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/89397",
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg21664641",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/89397",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container."
    },
    {
      "lang": "es",
      "value": "WebSphere eXtreme Scale Client versiones 7.1 hasta 8.6.0.4 de IBM, no aísla apropiadamente los datos almacenados en caché de diferentes usuarios, lo que permite a los usuarios autenticados remotos obtener información confidencial en circunstancias oportunistas al aprovechar el acceso al mismo contenedor web."
    }
  ],
  "lastModified": "2026-06-17T00:00:52.737",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64863DB8-00A6-4EDF-A451-5FFC89594B88",
              "versionEndIncluding": "8.6.0.4"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:7.0.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E75292F-3114-4BAE-AFB2-1DF58D08F2E4"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1B294AB-DC67-40AE-ABE2-F2FBD0C0457A"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "508DF17B-4141-42BD-B1D3-2BFF49A95B91"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D63B6556-7631-4DEC-B74A-E00E9E95B815"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17BB04FF-DA77-429F-85B0-38F3360FB5A9"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E85FDD6-7E95-44B7-9202-7DA706BF7F82"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "684B0290-464C-4AFE-B74C-8DF7926745D0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34646FFE-3403-4EC0-97E8-DBFADD312374"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26E425B9-DB4B-4E08-A665-AA4AE3FCF27E"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB7C5438-1006-4FAB-BB71-C4D920C630CA"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "485D6EB8-5419-45AB-A368-49897BFDBC0A"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9EA684D-93D4-4846-831A-4DEA42EF821E"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB4D202E-A04E-4710-9339-554291240998"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "813A4312-7D74-4600-B5F2-4DD158E05CFC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}