CVE-2013-6735
Status: ModifiedMedium (5)—
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.60%
- Percentile among all scored CVEs: 89
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-264
References
- http://osvdb.org/101255
- http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.html
- http://secunia.com/advisories/56161
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777
- http://www-01.ibm.com/support/docview.wss?uid=swg21660289
- http://www.securityfocus.com/archive/1/530552/100/0/threaded
- http://www.securityfocus.com/bid/64496
- http://www.securitytracker.com/id/1029539
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89591
- https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735
- http://osvdb.org/101255
- http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.html
- http://secunia.com/advisories/56161
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777
- http://www-01.ibm.com/support/docview.wss?uid=swg21660289
- http://www.securityfocus.com/archive/1/530552/100/0/threaded
- http://www.securityfocus.com/bid/64496
- http://www.securitytracker.com/id/1029539
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89591
- https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735
Raw JSON (NVD)
Show
{
"id": "CVE-2013-6735",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-12-22T15:16:04.443",
"references": [
{
"url": "http://osvdb.org/101255",
"source": "psirt@us.ibm.com"
},
{
"url": "http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://secunia.com/advisories/56161",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777",
"tags": [
"Not Applicable"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21660289",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/archive/1/530552/100/0/threaded",
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securityfocus.com/bid/64496",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://www.securitytracker.com/id/1029539",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/89591",
"source": "psirt@us.ibm.com"
},
{
"url": "https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "http://osvdb.org/101255",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/124611/IBM-Web-Content-Manager-XPath-Injection.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/56161",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1PI07777",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21660289",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/530552/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/64496",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1029539",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/89591",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_fix_available_for_unauthorized_information_retrieval_security_vulnerability_in_ibm_websphere_portal_cve_2013_6735",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL."
},
{
"lang": "es",
"value": "IBM Websphere Portal 6.0.0.x hasta 6.0.0.1, 6.0.1.x hasta 6.0.1.7, 6.1.0.x hasta 6.1.0.6 CF27, 6.1.5.x hasta 6.1.5.3 CF27, 7.0.0.x hasta 7.0.0.2 CF26, y 8.0.0.x hasta 8.0.0.1 CF08 permite a atacantes remotos obtener información Java Content Repository (JCR) sensile a través de una URL Web Content Manager (WCM) modificada."
}
],
"lastModified": "2026-06-17T00:00:52.840",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C753E1B-D81B-4995-877E-58EDD6F49DDB"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D54D4DB-FA55-47AE-9E19-FB8368FD40C8"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "092F8012-A1EE-46CE-B2B2-0604BF4ACBBA"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FC6A48A-E669-4AA0-AD83-85778A7B6C67"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F8C5AD9-2086-4131-A03C-02A89D822080"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82FC2F98-1E99-4B50-88D5-7A2904F4585C"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B7F74AC-2B5E-4B6C-9551-576A4F312BBB"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC51FA38-1C63-47F5-A4CF-1128396B62C9"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBCCA8DE-50EF-4154-AF48-A8E1AA2659B3"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.0.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF550E47-49FB-4EBC-83E7-4CFCB7279FEC"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E618064A-3D05-4DC6-9A47-0EDF2427642F"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DE74154-3E79-4D56-96C4-D8E644F1419D"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA915826-5D89-43E9-83E7-88973648302A"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5DB29F4-59AB-439C-91C4-CDF677676C26"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D6CA922-11EF-4315-A09A-B4A8937E4CF4"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "526738D7-1AF8-4A8F-B833-BA0E35973A3E"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13D6BE9C-16FD-4FB4-8A87-56B42C246316"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F1964FC-672F-4139-938F-A8EF9D86D9C2"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5B50CEA-AFC4-4B45-9954-519965237FC3"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0902AC0F-EA4D-4E65-A70A-15DE9B904B35"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:6.1.5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D808F95D-C6BD-43EB-B16C-66449977BCFE"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D303B0B9-CDAB-409B-AE44-512D4791C36F"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6ECEE98-B276-4ED6-AA5A-109EA57E9925"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E4FF84B-A17F-464B-A718-67C44D2C69BC"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C90EF7A4-8181-42C3-BB95-395D0DD94C14"
},
{
"criteria": "cpe:2.3:a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F40E0F5-B964-4BDC-828E-7571619F7C5B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}