cbcvebase.

Ibm Websphere Portal vulnerabilities

126 known vulnerabilities affecting ibm/websphere_portal.

Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15

Vulnerabilities

Page 3 of 7
CVE-2013-6735P4MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+24 more2013-12-22
CVE-2013-6735 [MEDIUM] CWE-264 CVE-2013-6735: IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
nvd
CVE-2016-0244P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2016-02-29
CVE-2016-0244 [MEDIUM] CVE-2016-0244: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5 Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243.
nvd
CVE-2013-6722P4MEDIUMCVSS 5.8v7.0.0.0v7.0.0.1+4 more2014-02-14
CVE-2013-6722 [MEDIUM] CVE-2013-6722: Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.0.0.1 CF09 allows remote attackers to cause a denial of service or modify data via unspecified vectors.
nvd
CVE-2014-6193P4MEDIUMCVSS 4.9v8.0.0.0v8.0.0.1+1 more2014-12-19
CVE-2014-6193 [MEDIUM] CVE-2014-6193: IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages settin IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.
nvd
CVE-2014-6125P4MEDIUMCVSS 6.8v8.5.0.02014-10-28
CVE-2014-6125 [MEDIUM] CWE-352 CVE-2014-6125: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows rem Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2014-6214P4MEDIUMCVSS 6.8v8.0.0.0v8.0.0.1+1 more2015-03-13
CVE-2014-6214 [MEDIUM] CWE-352 CVE-2014-6214: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 a Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2015-4998P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2015-12-21
CVE-2015-4998 [MEDIUM] CVE-2015-4998: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
nvd
CVE-2017-1303P4MEDIUMCVSS 6.1v7.0v8.0+2 more2017-07-31
CVE-2017-1303 [MEDIUM] CWE-79 CVE-2017-1303: IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scri IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125457.
nvd
CVE-2018-1401P4MEDIUMCVSS 6.1v8.0.0.0v8.5.0.0+4 more2018-02-09
CVE-2018-1401 [MEDIUM] CWE-79 CVE-2018-1401: IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability all IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138437.
nvd
CVE-2018-1361P4MEDIUMCVSS 6.1v8.5.0.0v9.0.0.0+2 more2018-01-11
CVE-2018-1361 [MEDIUM] CWE-79 CVE-2018-1361: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158.
nvd
CVE-2017-1217P4MEDIUMCVSS 6.1v8.5v9.02017-07-05
CVE-2017-1217 [MEDIUM] CWE-79 CVE-2017-1217: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857
nvd
CVE-2017-1761P4MEDIUMCVSS 6.1v7.0.0.0v7.0.0.2+8 more2018-02-09
CVE-2017-1761 [MEDIUM] CWE-79 CVE-2017-1761: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136005.
nvd
CVE-2017-1120P4MEDIUMCVSS 6.1v8.5v9.02017-03-27
CVE-2017-1120 [MEDIUM] CWE-79 CVE-2017-1120: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.
nvd
CVE-2015-1887P4MEDIUMCVSS 5.0v7.0.0.0v7.0.0.1+4 more2015-07-14
CVE-2015-1887 [MEDIUM] CWE-200 CVE-2015-1887: IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 al IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
nvd
CVE-2017-1698P4MEDIUMCVSS 5.3v7.0.0.0v8.0.0.0+6 more2017-12-27
CVE-2017-1698 [MEDIUM] CWE-200 CVE-2017-1698: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
nvd
CVE-2014-8912P4MEDIUMCVSS 5.0v6.0v6.0.0.1+30 more2015-10-28
CVE-2014-8912 [MEDIUM] CWE-284 CVE-2014-8912: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.
nvd
CVE-2014-4821P4MEDIUMCVSS 5.0v6.1.0.0v6.1.0.1+15 more2014-10-28
CVE-2014-4821 [MEDIUM] CWE-200 CVE-2014-4821: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.
nvd
CVE-2014-3056P4MEDIUMCVSS 5.0v7.0.0.0v7.0.0.1+3 more2014-07-29
CVE-2014-3056 [MEDIUM] CWE-200 CVE-2014-3056: The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive information about environment variables and JAR versions via unspecified vectors.
nvd
CVE-2017-1423P4MEDIUMCVSS 5.3v8.5.0.0v9.0.0.0+2 more2017-12-20
CVE-2017-1423 [MEDIUM] CWE-200 CVE-2017-1423: IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the We IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.
nvd
CVE-2013-6730P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-03-04
CVE-2013-6730 [MEDIUM] CWE-264 CVE-2013-6730: IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0. IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.
nvd
Ibm Websphere Portal vulnerabilities | cvebase