CVE-2013-6304
published 2014-03-06CVE-2013-6304: Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass…
PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.42%
69.8th percentile
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | algo_one | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
| ibm | algo_risk_application | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Algo Risk Application up to 2.4.1 Access Restriction path traversal (XFDB-88535 / BID-65929)
vuldb·2026-05-07·CVSS 4.0
CVE-2013-6304 [MEDIUM] IBM Algo Risk Application up to 2.4.1 Access Restriction path traversal (XFDB-88535 / BID-65929)
A vulnerability labeled as problematic has been found in IBM Algo Risk Application up to 2.4.1. Affected is an unknown function of the component Access Restriction. Executing a manipulation can lead to path traversal.
This vulnerability appears as CVE-2013-6304. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-24jg-h6v2-qfrg: Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2
ghsa_unreviewed·2022-05-17
CVE-2013-6304 [MEDIUM] CWE-22 GHSA-24jg-h6v2-qfrg: Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg21666093http://www.securityfocus.com/bid/65929https://exchange.xforce.ibmcloud.com/vulnerabilities/88535http://www-01.ibm.com/support/docview.wss?uid=swg21666093http://www.securityfocus.com/bid/65929https://exchange.xforce.ibmcloud.com/vulnerabilities/88535
2014-03-06
Published