LOW
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation
Published Nov 16, 2013
3.5
LOWCVSS 2.0
EPSS 1.46%
Description
The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.
Affected products
No data.
OR
- 7.0
- 7.0.0.1
- 7.0.0.2
- 7.0.0.3
- 7.0.0.4
- 7.0.0.5
- 7.0.0.6
- 7.0.0.7
- 7.0.0.8
- 7.0.0.9
- 7.0.0.10
- 7.0.0.11
- 7.0.0.12
- 7.0.0.13
- 7.0.0.14
- 7.0.0.15
- 7.0.0.16
- 7.0.0.17
- 7.0.0.18
- 7.0.0.19
- 7.0.0.21
- 7.0.0.22
- 7.0.0.23
- 7.0.0.24
- 7.0.0.25
- 7.0.0.27
- 7.0.0.29
- 8.0.0.0
- 8.0.0.1
- 8.0.0.2
- 8.0.0.3
- 8.0.0.4
- 8.0.0.5
- 8.0.0.6
- 8.0.0.7
- 8.5.0.0
- 8.5.0.1
- 8.5.0.2
- 8.5.5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www-01.ibm.com/support/docview.wss?&uid=swg21651880 x_refsource_CONFIRMVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM92313 vendor-advisoryx_refsource_AIXAPAR
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-5254 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87476 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://www-01.ibm.com/support/docview.wss?&uid=swg21651880 | x_refsource_CONFIRMVendor Advisory | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1PM92313 | vendor-advisoryx_refsource_AIXAPAR | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-5254 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/87476 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Nov 16, 2013
Updated Aug 6, 2024
Reserved Aug 22, 2013
Link CVE-2013-5414
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-5254 Assigner ibm
Published Nov 16, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-5254