IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, which allows remote authenticated users to obtain sensitive information in opportunistic circumstances by leveraging access to the same web container.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1PI06341 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21664641 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/89397 - |
Information
Published : 2014-02-22 21:55
Updated : 2024-11-21 01:59
NVD link : CVE-2013-6734
Mitre link : CVE-2013-6734
CVE.ORG link : CVE-2013-6734
JSON object : View
Products Affected
ibm
- websphere_extreme_scale_client
CWE
CWE-264
Permissions, Privileges, and Access Controls