CVE-2013-0513 Information

Description

IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 create a service that lacks \ (double quote) characters in the service path which allows local users to gain privileges via a Trojan horse program related to an \Unquoted Service Path Enumeration\ vulnerability.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg21626264 http://www-01.ibm.com/support/docview.wss?uid=swg21631304 https://exchange.xforce.ibmcloud.com/vulnerabilities/82594

Share on: