{"api_version":"1","generated_at":"2026-07-23T11:48:17+00:00","cve":"CVE-2013-4404","urls":{"html":"https://cve.report/CVE-2013-4404","api":"https://cve.report/api/cve/CVE-2013-4404.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-4404","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-4404"},"summary":{"title":"CVE-2013-4404","description":"cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.","state":"PUBLISHED","assigner":"redhat","published_at":"2013-12-23 22:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2013-1851.html","name":"http://rhn.redhat.com/errata/RHSA-2013-1851.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-1852.html","name":"http://rhn.redhat.com/errata/RHSA-2013-1852.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038","name":"http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"995038 – (CVE-2013-4404) CVE-2013-4404 cumin: missing authorization checks in forms, charts, and csv export widgets","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-4404","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4404","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"4404","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_mrg","cpe6":"2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"4404","cve":"CVE-2013-4404","epss":"0.002160000","percentile":"0.439470000","score_date":"2026-04-30","updated_at":"2026-05-01 00:10:53"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T16:45:14.748Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038"},{"name":"RHSA-2013:1851","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1851.html"},{"name":"RHSA-2013:1852","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1852.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-12-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-01-07T13:57:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038"},{"name":"RHSA-2013:1851","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1851.html"},{"name":"RHSA-2013:1852","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-1852.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-4404","datePublished":"2013-12-23T22:00:00.000Z","dateReserved":"2013-06-12T00:00:00.000Z","dateUpdated":"2024-08-06T16:45:14.748Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-12-23 22:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_mrg:2.4:*:*:*:*:*:*:*","matchCriteriaId":"DBE39763-E666-4001-BDD3-0B11D4531366"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"4404","Ordinal":"1","Title":"CVE-2013-4404","CVE":"CVE-2013-4404","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"4404","Ordinal":"1","NoteData":"cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.","Type":"Description","Title":"CVE-2013-4404"},{"CveYear":"2013","CveId":"4404","Ordinal":"2","NoteData":"2013-12-23","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"4404","Ordinal":"3","NoteData":"2014-01-07","Type":"Other","Title":"Modified"}]}}}