cbcvebase.

Ibm Websphere Portal vulnerabilities

126 known vulnerabilities affecting ibm/websphere_portal.

Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15

Vulnerabilities

Page 1 of 7
CVE-2008-3423P3HIGHCVSS 7.5v5.1.0.0v5.1.0.1+9 more2008-08-04
CVE-2008-3423 [HIGH] CWE-264 CVE-2008-3423: IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.
nvd
CVE-2017-1577P3HIGHCVSS 7.5v7.0.0.0v7.0.0.1+9 more2017-09-28
CVE-2017-1577 [HIGH] CWE-22 CVE-2017-1577: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 132117.
nvd
CVE-2010-0714P4MEDIUMCVSS 4.3PoCv5.1.0.0v5.1.0.1+22 more2010-02-26
CVE-2010-0714 [MEDIUM] CWE-79 CVE-2010-0714: Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for Web
nvd
CVE-2014-3055P3HIGHCVSS 7.5v7.0.0.0v7.0.0.1+3 more2014-07-29
CVE-2014-3055 [HIGH] CWE-89 CVE-2014-3055: SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2015-7472P3HIGHCVSS 7.2v6.1.0.0v6.1.0.1+15 more2016-02-15
CVE-2015-7472 [HIGH] CVE-2015-7472: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.
nvd
CVE-2017-1156P3HIGHCVSS 8.8v8.5v9.02017-05-05
CVE-2017-1156 [HIGH] CWE-601 CVE-2017-1156: IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow
nvd
CVE-2015-4997P3MEDIUMCVSS 6.8v8.5.0.02015-10-29
CVE-2015-4997 [MEDIUM] CWE-264 CVE-2015-4997: IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restriction IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request.
nvd
CVE-2014-0910P4LOWCVSS 3.5PoCv7.0.0.0v7.0.0.1+12 more2014-06-18
CVE-2014-0910 [LOW] CWE-79 CVE-2014-0910: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5 Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-4808P3MEDIUMCVSS 6.5v6.1.0.0v6.1.0.1+14 more2014-10-28
CVE-2014-4808 [MEDIUM] CVE-2014-4808: Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors.
nvd
CVE-2013-2951P3HIGHCVSS 7.8v7.0.0.0v7.0.0.1+3 more2018-07-11
CVE-2013-2951 [HIGH] CWE-255 CVE-2013-2951: IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.
nvd
CVE-2015-1886P4HIGHCVSS 7.8v6.1.0.0v6.1.0.1+15 more2015-04-27
CVE-2015-1886 [HIGH] CWE-399 CVE-2015-1886: The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1 The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
nvd
CVE-2015-7419P4HIGHCVSS 7.8v8.0.0.1v8.5.0.02015-11-14
CVE-2015-7419 [HIGH] CWE-399 CVE-2015-7419: IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a de IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
nvd
CVE-2015-1943P4HIGHCVSS 7.8v6.1.0.0v6.1.0.1+15 more2015-09-14
CVE-2015-1943 [HIGH] CWE-399 CVE-2015-1943: IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0 IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
nvd
CVE-2014-0918P4HIGHCVSS 7.1v6.1.0.0v6.1.0.1+14 more2014-05-16
CVE-2014-0918 [HIGH] CWE-22 CVE-2014-0918: Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 th Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2018-1420P4MEDIUMCVSS 6.5v7.0.0.0v7.0.0.1+9 more2018-10-01
CVE-2018-1420 [MEDIUM] CWE-732 CVE-2018-1420: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box con IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
nvd
CVE-2016-2901P4HIGHCVSS 8.8v8.5.0.02016-06-26
CVE-2016-2901 [HIGH] CWE-352 CVE-2016-2901: Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Cross-site request forgery (CSRF) vulnerability in the PA_Theme_Creator application in IBM WebSphere Portal 8.5 CF08 through CF10 and Web Content Manager allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2008-5675P4CRITICALCVSS 10.0≤ 6.0.1.4v6.0.0.0+4 more2008-12-19
CVE-2008-5675 [CRITICAL] CWE-264 CVE-2008-5675: Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack v Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuthTAI."
nvd
CVE-2007-3127P4MEDIUMCVSS 5.0PoCv1.02007-06-19
CVE-2007-3127 [MEDIUM] CVE-2007-3127: content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain se content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.
nvd
CVE-2012-4834P4MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+1 more2012-11-30
CVE-2012-4834 [MEDIUM] CWE-22 CVE-2012-4834: Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.
nvd
CVE-2015-1899P4HIGHCVSS 7.8v8.5.0.02015-05-25
CVE-2015-1899 [HIGH] CWE-399 CVE-2015-1899: IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU cons IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
nvd
Ibm Websphere Portal vulnerabilities | cvebase