CVE-2013-6304
Published Mar 6, 2014
Last updated 7 years ago
Overview
- Description
- Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:algo_one:4.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A672407B-4966-4A89-BF1B-2644CEAF172B" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.4.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9AFB152-35CB-4EA6-BE66-BCF27FBBE746" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF0E4220-6286-455E-9EAE-6ED51F434E74" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6079F599-45D2-48B7-8715-0A1979C32498" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66AA4D0B-2452-43C1-9488-351CD11D7713" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AA31B8F-8479-43EC-BF96-3B14D82E395E" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E69B21A-CDD4-4FA8-BC03-041C036431C2" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "286D5406-9716-49E0-A4B3-B7DFBA318699" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F6ABE80-7A6F-45A9-9D90-DF4A988A6ED4" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2577F25B-4212-490E-876C-7FBBCBFEC30F" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8749B6D1-44CF-48BE-A56D-D719AF11F19C" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E286D72D-FA08-4C08-88B2-EC8910703031" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E08CA13F-81EE-4B87-8F16-D1A396729044" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EC64A5A-8237-46C3-A34D-AF88983B7952" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:2.5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2F5C504-530B-47B5-AD99-450E358D3566" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21B053FB-FEB5-4DF0-B531-0D767D2DF563" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "191C565F-6BDB-43A1-BAA8-D6BBEF9796DE" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96B2C69F-9F87-4E6E-8840-DA7BEFF7582E" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E75FCD1-E3D9-4CAE-860F-7B21499CBCD3" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB72206E-F364-44D9-B112-03DF9630071D" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ECFE5DBB-2684-4450-8364-722A78F31FED" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "484760AB-B08C-49B6-9D38-06979A7CA0F1" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2F9CBB1-AA31-43F2-8997-10454A3769DB" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5945F332-84B2-4131-AA75-27772E0F54D8" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "192C0372-DB7E-47A3-909C-FEE89A904770" }, { "criteria": "cpe:2.3:a:ibm:algo_risk_application:4.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "127A6A8D-4453-4F19-9593-53722BD6BA52" } ], "operator": "OR" } ] } ]