CVE-2013-4053Improper Input Validation in IBM Websphere Application Server

Severity
6.8MEDIUMNVD
EPSS
0.4%
top 39.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 20
Latest updateMay 17

Description

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDibm/websphere_application19 versions+18

🔴Vulnerability Details

2
GHSA
GHSA-jw94-7cxh-2x3r: The WS-Security implementation in IBM WebSphere Application Server (WAS) 62022-05-17
CVEList
CVE-2013-4053: The WS-Security implementation in IBM WebSphere Application Server (WAS) 62013-09-20
CVE-2013-4053 — Improper Input Validation in IBM | cvebase