PT-2014-3178 · Ibm · Ibm Websphere Dashboard Framework

Published

2014-02-14

·

Updated

2017-08-29

·

CVE-2013-6728

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Dashboard Framework versions 6.1.5 through 7.0.1
Description The issue concerns the charting component in IBM WebSphere Dashboard Framework, which has incorrect security constraints for a temporary directory. This allows remote attackers to view or delete image files.
Recommendations For versions 6.1.5 through 7.0.1, consider restricting access to the temporary directory to prevent unauthorized viewing or deletion of image files. As a temporary workaround, restrict access to the charting component until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6728

Affected Products

Ibm Websphere Dashboard Framework