CVE-2013-6735
Summary
| CVE | CVE-2013-6735 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-12-22 15:16:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS: 0.035990000 probability, percentile 0.881970000 (date 2026-07-21)
Problem Types: CWE-264 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Portal | 6.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.5 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.6 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.7 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.5 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.6 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.3 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Web Content Manager XPath Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| IBM Blogs | af854a3a-2127-422b-91ae-364da2661108 | www-304.ibm.com | Third Party Advisory, VDB Entry |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM Security Bulletin: Fix available for Unauthorized Information Retrieval Security Vulnerability in IBM WebSphere Portal (CVE-2013-6735) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Not Applicable |
| IBM Web Content Manager 'LIBRARY' Parameter XPath Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Advisory SA56161 - IBM WebSphere Portal XPath Injection Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/101255 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM WebSphere Portal XPath Injection Flaw Lets Remote Users Obtain Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.