| CVE ID | CVE-2013-5398 | 
| CVSS SCORE | 5.0, AV:N/AC:L/Au:N/C:P/I:N/A:N | 
| AFFECTED VENDORS | 
                            
                            
                            IBM | 
                    
| AFFECTED PRODUCTS | 
                            
                            
                            Rational Focal Point | 
                    
| VULNERABILITY DETAILS | 
                             
 The specific flaw exists within com.telelogic.focalpoint.pres.controller.RequestAccessController servlet which contains a file disclosure vulnerability in the file variable. A remote attacker could gain access to configuration files which could lead to remote code execution in the context of the process.   | 
                    
| ADDITIONAL DETAILS | 
                            
                            
                            IBM has issued an update to correct this vulnerability. More details can be found at:
                             http://www-01.ibm.com/support/docview.wss?uid=swg21654471  | 
                    
| DISCLOSURE TIMELINE | 
                            
  | 
                    
| CREDIT | Andrea Micalizzi aka rgod |