MEDIUM · 4.9

CVE-2013-4012

IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which al...

Vulnerability Description

IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

CVSS Score

4.9

MEDIUM

AV:N/AC:M/Au:S/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmWebsphere Portal8.0.0.0
IbmContent Template Catalog4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4012?

CVE-2013-4012 is a vulnerability with a CVSS score of 4.9 (MEDIUM). IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which al...

How severe is CVE-2013-4012?

CVE-2013-4012 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4012?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Websphere Portal, Ibm Content Template Catalog.