CVE-2013-0544
published 2013-04-24CVE-2013-0544: Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before…
PriorityP421medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
3.15%
86.6th percentile
Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
bugzilla·2012-11-30·CVSS 4.3
CVE-2012-5604 [MEDIUM] CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
Og Maciel of Red Hat reports:
After configuring my system to use ActiveDirectory as the authentication
method, I was able to login via the web ui without having to provide a
password when using Windows ADS as the LDAP authentication backend.
Discussion:
Acknowledgements:
This issue was discovered by Og Maciel of Red Hat.
---
This issue did not affect CloudForms 1.0, which did not include this component. The issue is fixed in CloudFroms 1.1. No released version of CloudFroms was affected by this issue.
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
Bugzilla
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
bugzilla·2012-11-30·CVSS 5.5
CVE-2012-5603 [MEDIUM] CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
Lukas Zapletal of Red Hat reports:
Regular user (somebody with username and password) and a consumer UUID of any
system can download the consumer certificate and consume content or modify
data without permission to do that.
Discussion:
Acknowledgements:
This issue was discovered by Lukas Zapletal of Red Hat.
---
This issue has been addressed in following products:
CloudForms for RHEL 6
CloudForms Tools for RHEL 5
Via RHSA-2012:1543 https://rhn.redhat.com/errata/RHSA-2012-1543.html
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
---
The Red Hat Security Response Team has rated this
http://www-01.ibm.com/support/docview.wss?&uid=swg21632423http://www-01.ibm.com/support/docview.wss?uid=swg1PM82468https://exchange.xforce.ibmcloud.com/vulnerabilities/82760http://www-01.ibm.com/support/docview.wss?&uid=swg21632423http://www-01.ibm.com/support/docview.wss?uid=swg1PM82468https://exchange.xforce.ibmcloud.com/vulnerabilities/82760
2013-04-24
Published