CVE-2013-4006
IBM WebSphere Application Server Liberty Profile < 8.5.5.1 - Information Disclosure via Weak File Permissions
Title source: llmDescription
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.
References (3)
Core 3
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM90472
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?&uid=swg21651880
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85273
Scores
EPSS
0.0131
EPSS Percentile
67.7%
Details
CWE
CWE-310
Status
published
Products (4)
ibm/websphere_application_server
8.5.0.0
ibm/websphere_application_server
8.5.0.1
ibm/websphere_application_server
8.5.0.2
ibm/websphere_application_server
8.5.5.0
Published
Nov 18, 2013
Tracked Since
Feb 18, 2026