Vulnerability Description
SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6331.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Algo One | 4.7.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21666110
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88532
- http://www-01.ibm.com/support/docview.wss?uid=swg21666110
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88532
FAQ
What is CVE-2013-6302?
CVE-2013-6302 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoW...
How severe is CVE-2013-6302?
CVE-2013-6302 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6302?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Algo One.