CVE-2013-6305
Last modified
CVE-2013-6305 is a vulnerability of currently unknown severity. IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Platform Symphony | 5.2 |
| Ibm | Platform Symphony | 6.1.0.1 |
References
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1020528Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1020528Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-6305?
How severe is CVE-2013-6305?
How do I fix CVE-2013-6305?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-6299Cross-site scripting (XSS) vulnerability in IBM Algo One, as…
- CVE-2013-6300Cross-site scripting (XSS) vulnerability in IBM Algo One, as…
- CVE-2013-6301Cross-site scripting (XSS) vulnerability in IBM Algo One, as…
- CVE-2013-6302SQL injection vulnerability in IBM Algo One, as used in Meta…
- CVE-2013-6303Directory traversal vulnerability in IBM Algo One, as used i…
- CVE-2013-6304Multiple directory traversal vulnerabilities in Algo Risk Ap…
- CVE-2013-6306Unspecified vulnerability on IBM Power 7 Systems 740 before …
- CVE-2013-6307Cross-site scripting (XSS) vulnerability in IBM Security QRa…
- CVE-2013-6308IBM Marketing Platform 9.1 before FP2 allows remote authenti…
- CVE-2013-6309IBM Marketing Platform 9.1 before FP2 allows remote authenti…
- CVE-2013-6310Cross-site scripting (XSS) vulnerability in IBM Marketing Pl…
- CVE-2013-6311SQL injection vulnerability in IBM Marketing Platform 9.1 be…
Are you affected by CVE-2013-6305?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
