CVE-2013-6719 describes a remote command injection vulnerability in the delivery.php component of the Passive Capture Application (PCA) web console within IBM Tealeaf CX versions 7.x, 8.x through 8.6, and specific versions of 8.7 and 8.8. An authenticated attacker can exploit this flaw by injecting shell metacharacters into the testconn_host parameter. The vulnerability carries a CVSS score of 6.0, indicating a medium severity, and allows for partial confidentiality, integrity, and availability impact due to the potential for arbitrary command execution. While not actively exploited in the wild (no KEV entry), a public exploit (EDB-32546) exists, demonstrating its exploitability. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:a:ibm:tealeaf_cx:7.1:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:a:ibm:tealeaf_cx:7.2:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:ibm:tealeaf_cx:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:ibm:tealeaf_cx:8.1:*:*:*:*:*:*:* | ||
8.2CPE matchmatch criteria | cpe:2.3:a:ibm:tealeaf_cx:8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.