CVE-2013-6734

IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_extreme_scale_client:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:7.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:7.1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_extreme_scale_client:8.6.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:59

Type Values Removed Values Added
References () http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341 - () http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341 -
References () http://www-01.ibm.com/support/docview.wss?uid=swg21664641 - Vendor Advisory () http://www-01.ibm.com/support/docview.wss?uid=swg21664641 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/89397 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/89397 -

Information

Published : 2014-02-22 21:55

Updated : 2024-11-21 01:59


NVD link : CVE-2013-6734

Mitre link : CVE-2013-6734

CVE.ORG link : CVE-2013-6734


JSON object : View

Products Affected

ibm

  • websphere_extreme_scale_client
CWE
CWE-264

Permissions, Privileges, and Access Controls