CVE-2015-1921
published 2015-05-25CVE-2015-1921: Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web…
PriorityP422medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.43%
82.5th percentile
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4882 OpenJDK: incorrect String object deserialization in IIOPInputStream (CORBA, 8076387)
bugzilla·2015-10-20·CVSS 5.0
CVE-2015-4882 [MEDIUM] CVE-2015-4882 OpenJDK: incorrect String object deserialization in IIOPInputStream (CORBA, 8076387)
CVE-2015-4882 OpenJDK: incorrect String object deserialization in IIOPInputStream (CORBA, 8076387)
A flaw was found in the way the IIOPInputStream class in the CORBA component of OpenJDK performed deserialization of String objects. An untrusted Java application or applet could use this flaw to crash the Java Virtual Machine.
Discussion:
Public now via Oracle Critical Patch Update - October 2015. Fixed in Oracle Java SE 6u105, 7u91, and 8u65.
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:1921 https://rhn.redhat.com/errata/RHSA-2015-1921.html
---
This issue has been addressed in the following products:
Red Hat Enterpri
Bugzilla
CVE-2015-4803 OpenJDK: inefficient use of hash tables and lists during XML parsing (JAXP, 8068842)
bugzilla·2015-10-20·CVSS 5.0
CVE-2015-4803 [MEDIUM] CVE-2015-4803 OpenJDK: inefficient use of hash tables and lists during XML parsing (JAXP, 8068842)
CVE-2015-4803 OpenJDK: inefficient use of hash tables and lists during XML parsing (JAXP, 8068842)
It was discovered that the JAXP component of OpenJDK did not use efficient data structures to store data from parsed XML documents. A specially-crafted XML input could cause a Java application using JAXP to use an excessive amount of CPU time by e.g. triggering hash collisions.
Discussion:
Public now via Oracle Critical Patch Update - October 2015. Fixed in Oracle Java SE 6u105, 7u91, and 8u65.
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Via RHSA-2015:1921 https://rhn.redhat.com/errata/RHSA-2015-1921.html
---
This issue has been add
http://www-01.ibm.com/support/docview.wss?uid=swg1PI38632http://www-01.ibm.com/support/docview.wss?uid=swg21884060http://www.securityfocus.com/bid/74705http://www-01.ibm.com/support/docview.wss?uid=swg1PI38632http://www-01.ibm.com/support/docview.wss?uid=swg21884060http://www.securityfocus.com/bid/74705
2015-05-25
Published