CVE-2013-5446

IBM WebSphere DataPower XC10 <2.5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21653546
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87910
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC93164
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC96617

Scores

EPSS 0.0168
EPSS Percentile 74.5%

Details

Status published
Products (3)
ibm/websphere_datapower_xc10_appliance
ibm/websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm/websphere_datapower_xc10_appliance_firmware 2.5.0.0
Published Oct 22, 2013
Tracked Since Feb 18, 2026