PT-2014-3178 · Ibm · Ibm Websphere Dashboard Framework

Publicado

2014-02-14

·

Atualizado

2017-08-29

·

CVE-2013-6728

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Dashboard Framework versions 6.1.5 through 7.0.1
Description The issue concerns the charting component in IBM WebSphere Dashboard Framework, which has incorrect security constraints for a temporary directory. This allows remote attackers to view or delete image files.
Recommendations For versions 6.1.5 through 7.0.1, consider restricting access to the temporary directory to prevent unauthorized viewing or deletion of image files. As a temporary workaround, restrict access to the charting component until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6728

Produtos afetados

Ibm Websphere Dashboard Framework