CVE-2013-0520
Summary
| CVE | CVE-2013-0520 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-05-10 11:42:29 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 allows remote authenticated users to obtain sensitive Java stack-trace information by providing invalid input data. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Sterling Secure Proxy | 3.2.0.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.3.0.1 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.0.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.1.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.1.2 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.1.5 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.1.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Multiple security vulnerabilities addressed in IBM Sterling Secure Proxy (CVE-2013-0518, CVE-2013-0519, CVE-2013-0520) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.