Ibm Websphere Portal vulnerabilities
126 known vulnerabilities affecting ibm/websphere_portal.
Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15
Vulnerabilities
Page 2 of 7
CVE-2018-1672P4MEDIUMCVSS 6.3v7.0.0.0v7.0.0.1+9 more2018-10-01
CVE-2018-1672 [MEDIUM] CWE-287 CVE-2018-1672: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impe
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.
nvd
CVE-2007-3128P4MEDIUMCVSS 6.4v1.02007-06-19
CVE-2007-3128 [MEDIUM] CVE-2007-3128: SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allow
SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.
nvd
CVE-2012-2181P4MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+1 more2012-07-03
CVE-2012-2181 [MEDIUM] CWE-22 CVE-2012-2181: Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 bef
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2015-7447P4MEDIUMCVSS 5.3v6.1.0.0v6.1.0.1+15 more2015-12-31
CVE-2015-7447 [MEDIUM] CWE-200 CVE-2015-7447: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF09 allows remote attackers to bypass intended Portal AccessControl REST API access restrictions and obtain sensitive information via unspecified vectors.
nvd
CVE-2014-4746P4MEDIUMCVSS 5.0v8.0.0.0v8.5.0.02014-08-12
CVE-2014-4746 [MEDIUM] CWE-200 CVE-2014-4746: IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes
IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whether the intranet host exists, which allows remote attackers to map the intranet network via a series of requests.
nvd
CVE-2010-1348P4HIGHCVSS 7.5v6.0.1.1v6.1.0.0+2 more2010-04-12
CVE-2010-1348 [HIGH] CVE-2010-1348: Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6
Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors.
nvd
CVE-2009-4153P4HIGHCVSS 7.5v6.1.0.0v6.1.0.1+1 more2009-12-02
CVE-2009-4153 [HIGH] CVE-2009-4153: Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 ha
Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to the work directory.
nvd
CVE-2014-0954P4MEDIUMCVSS 6.8v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0954 [MEDIUM] CWE-20 CVE-2014-0954: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.
nvd
CVE-2016-0245P4MEDIUMCVSS 5.4v8.0.0.0v8.0.0.1+1 more2016-02-29
CVE-2016-0245 [MEDIUM] CVE-2016-0245: The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allow
The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvd
CVE-2013-5454P4MEDIUMCVSS 4.3v6.0.0.0v6.0.0.1+24 more2013-11-18
CVE-2013-5454 [MEDIUM] CWE-200 CVE-2013-5454: IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.
IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.
nvd
CVE-2016-5954P4MEDIUMCVSS 6.5v6.1.0.0v6.1.0.1+15 more2016-09-12
CVE-2016-5954 [MEDIUM] CWE-284 CVE-2016-5954: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.
nvd
CVE-2013-3016P4MEDIUMCVSS 5.0v6.1.0.0v7.0.0.0+2 more2013-08-21
CVE-2013-3016 [MEDIUM] CWE-264 CVE-2013-3016: IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a cr
IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serveServletsByClassnameEnabled setting.
nvd
CVE-2015-7428P4HIGHCVSS 7.4v8.0.0.0v8.0.0.1+1 more2016-02-29
CVE-2015-7428 [HIGH] CVE-2015-7428: Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0
Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
nvd
CVE-2018-1736P4MEDIUMCVSS 6.1v7.0.0.0v7.0.0.1+9 more2018-09-27
CVE-2018-1736 [MEDIUM] CWE-601 CVE-2018-1736: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attack
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. Thi
nvd
CVE-2015-4993P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2015-12-21
CVE-2015-4993 [MEDIUM] CWE-79 CVE-2015-4993: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.
nvd
CVE-2018-1673P4MEDIUMCVSS 6.1v7.0.0.0v7.0.0.1+9 more2018-10-12
CVE-2018-1673 [MEDIUM] CWE-79 CVE-2018-1673: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.
nvd
CVE-2018-1716P4MEDIUMCVSS 6.1v7.0.0.0v7.0.0.1+9 more2018-09-27
CVE-2018-1716 [MEDIUM] CWE-79 CVE-2018-1716: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147164.
nvd
CVE-2018-1483P4MEDIUMCVSS 6.1v8.5.0.0v9.0+1 more2018-04-11
CVE-2018-1483 [MEDIUM] CWE-79 CVE-2018-1483: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140918.
nvd
CVE-2018-1416P4MEDIUMCVSS 6.1v7.0.0.0v7.0.0.1+9 more2018-02-27
CVE-2018-1416 [MEDIUM] CWE-79 CVE-2018-1416: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138822.
nvd
CVE-2016-0243P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2016-02-29
CVE-2016-0243 [MEDIUM] CWE-79 CVE-2016-0243: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244.
nvd