Permissions, Privileges, and Access Controls in WebSphere Portal - CVE-2013-6730
Published: March 5, 2014 / Updated: August 10, 2020
WebSphere Portal
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.