{"api_version":"1","generated_at":"2026-07-23T12:05:00+00:00","cve":"CVE-2013-5452","urls":{"html":"https://cve.report/CVE-2013-5452","api":"https://cve.report/api/cve/CVE-2013-5452.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-5452","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-5452"},"summary":{"title":"CVE-2013-5452","description":"IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","state":"PUBLISHED","assigner":"ibm","published_at":"2013-12-19 22:55:04","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PJ40949","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1PJ40949","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PJ40949: BPF IS SUSCEPTIBLE TO XXE (XML EXTERNAL ENTITY) ATTACKS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033734","name":"http://www.securitytracker.com/id/1033734","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Business Process Manager XML External Entity Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-304.ibm.com/support/docview.wss?uid=swg21963014","name":"http://www-304.ibm.com/support/docview.wss?uid=swg21963014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Bulletin: IBM Business Process Manager (BPM) document store is susceptible to XXE (XML External Entity) attacks. (CVE-2013-5452)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21660343","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21660343","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/88192","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/88192","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-5452","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5452","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"5452","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"filenet_business_process_framework","cpe6":"4.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"5452","cve":"CVE-2013-5452","epss":"0.002950000","percentile":"0.527090000","score_date":"2026-04-30","updated_at":"2026-05-01 00:10:53"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T17:15:20.211Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ibm-filenetbpf-cve20135452-xxe(88192)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/88192"},{"name":"1033734","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033734"},{"name":"PJ40949","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PJ40949"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-304.ibm.com/support/docview.wss?uid=swg21963014"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21660343"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-12-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"ibm-filenetbpf-cve20135452-xxe(88192)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/88192"},{"name":"1033734","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033734"},{"name":"PJ40949","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PJ40949"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-304.ibm.com/support/docview.wss?uid=swg21963014"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21660343"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2013-5452","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ibm-filenetbpf-cve20135452-xxe(88192)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/88192"},{"name":"1033734","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033734"},{"name":"PJ40949","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PJ40949"},{"name":"http://www-304.ibm.com/support/docview.wss?uid=swg21963014","refsource":"CONFIRM","url":"http://www-304.ibm.com/support/docview.wss?uid=swg21963014"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21660343","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21660343"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2013-5452","datePublished":"2013-12-19T22:00:00.000Z","dateReserved":"2013-08-22T00:00:00.000Z","dateUpdated":"2024-08-06T17:15:20.211Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-12-19 22:55:04","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:filenet_business_process_framework:4.1.0:*:*:*:*:*:*:*","matchCriteriaId":"2E67286C-C410-4924-BC1D-C0D992175FAD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"5452","Ordinal":"1","Title":"CVE-2013-5452","CVE":"CVE-2013-5452","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"5452","Ordinal":"1","NoteData":"IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","Type":"Description","Title":"CVE-2013-5452"},{"CveYear":"2013","CveId":"5452","Ordinal":"2","NoteData":"2013-12-19","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"5452","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}