Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-0523

EPSS 0.16% · P36
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-0523

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM WebSphere Commerce Enterprise 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM WebSphere Commerce Enterprise是美国IBM公司的一套电子商务解决方案。该方案主要用于大容量的B2C和B2B业务模型以及多个电子商务站点的高级平台。 IBM WebSphere Commerce Enterprise 5.6.x至5.6.1.5版本,6.0.x至6.0.0.11版本,7.0.x至7.0.0.7版本中存在漏洞,该漏洞源于程序对storefront Web请求没有使用适当的加密算法。远程攻击者可通过padding oracle攻击目标特定的UTF-8处理kry
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-0523

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-0523

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-06-21 · 23 CVEs total

CVE-2013-0551IBM Application Manager for Smart Business/ITM 拒绝服务漏洞
CVE-2013-3379Cisco TelePresence TC软件权限许可和访问控制漏洞
CVE-2013-3378Cisco TelePresence TC/TE软件输入验证漏洞
CVE-2013-3377Cisco TelePresence TC/TE软件资源管理错误漏洞
CVE-2013-2173WordPress ‘crypt_private()’方法远程拒绝服务漏洞
CVE-2013-3035IBM AIX IPv6包处理远程拒绝服务漏洞
CVE-2013-0534IBM Sametime Connect客户端本地信息泄露漏洞
CVE-2013-0529IBM Sterling Connect:Direct 浏览器安全漏洞
CVE-2013-0527IBM Sterling Connect:Direct 浏览器安全漏洞
CVE-2013-2961IBM Application Manager for Smart Business/ITM 安全漏洞
CVE-2013-2960IBM Application Manager for Smart Business/ITM 缓冲区溢出漏洞
CVE-2013-3392Cisco WebEx Social 多个跨站请求伪造漏洞
CVE-2013-0548IBM Application Manager For Smart Business/ITM 多个跨站脚本漏洞
CVE-2013-0536IBM Notes Multi User Profile Cleanup Service 本地提权漏洞
CVE-2012-6572Drupal 跨站脚本漏洞
CVE-2013-3250WordPress WP Maintenance Mode插件跨站请求伪造漏洞
CVE-2013-2110PHP 基于堆的缓冲区溢出漏洞
CVE-2013-4636PHP 输入验证错误漏洞
CVE-2013-4635PHP 数字错误漏洞
CVE-2013-4615多款Canon打印机存远程拒绝服务漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-0523

No comments yet


Leave a comment