Ibm Websphere Portal vulnerabilities
126 known vulnerabilities affecting ibm/websphere_portal.
Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15
Vulnerabilities
Page 3 of 7
CVE-2013-6735P4MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+24 more2013-12-22
CVE-2013-6735 [MEDIUM] CWE-264 CVE-2013-6735: IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27,
IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
nvd
CVE-2016-0244P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2016-02-29
CVE-2016-0244 [MEDIUM] CVE-2016-0244: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243.
nvd
CVE-2013-6722P4MEDIUMCVSS 5.8v7.0.0.0v7.0.0.1+4 more2014-02-14
CVE-2013-6722 [MEDIUM] CVE-2013-6722: Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere
Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.0.0.1 CF09 allows remote attackers to cause a denial of service or modify data via unspecified vectors.
nvd
CVE-2014-6193P4MEDIUMCVSS 4.9v8.0.0.0v8.0.0.1+1 more2014-12-19
CVE-2014-6193 [MEDIUM] CVE-2014-6193: IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages settin
IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.
nvd
CVE-2014-6125P4MEDIUMCVSS 6.8v8.5.0.02014-10-28
CVE-2014-6125 [MEDIUM] CWE-352 CVE-2014-6125: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows rem
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2014-6214P4MEDIUMCVSS 6.8v8.0.0.0v8.0.0.1+1 more2015-03-13
CVE-2014-6214 [MEDIUM] CWE-352 CVE-2014-6214: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 a
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2015-4998P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2015-12-21
CVE-2015-4998 [MEDIUM] CVE-2015-4998: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
nvd
CVE-2017-1303P4MEDIUMCVSS 6.1v7.0v8.0+2 more2017-07-31
CVE-2017-1303 [MEDIUM] CWE-79 CVE-2017-1303: IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scri
IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125457.
nvd
CVE-2018-1401P4MEDIUMCVSS 6.1v8.0.0.0v8.5.0.0+4 more2018-02-09
CVE-2018-1401 [MEDIUM] CWE-79 CVE-2018-1401: IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability all
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138437.
nvd
CVE-2018-1361P4MEDIUMCVSS 6.1v8.5.0.0v9.0.0.0+2 more2018-01-11
CVE-2018-1361 [MEDIUM] CWE-79 CVE-2018-1361: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158.
nvd
CVE-2017-1217P4MEDIUMCVSS 6.1v8.5v9.02017-07-05
CVE-2017-1217 [MEDIUM] CWE-79 CVE-2017-1217: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857
nvd
CVE-2017-1761P4MEDIUMCVSS 6.1v7.0.0.0v7.0.0.2+8 more2018-02-09
CVE-2017-1761 [MEDIUM] CWE-79 CVE-2017-1761: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136005.
nvd
CVE-2017-1120P4MEDIUMCVSS 6.1v8.5v9.02017-03-27
CVE-2017-1120 [MEDIUM] CWE-79 CVE-2017-1120: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.
nvd
CVE-2015-1887P4MEDIUMCVSS 5.0v7.0.0.0v7.0.0.1+4 more2015-07-14
CVE-2015-1887 [MEDIUM] CWE-200 CVE-2015-1887: IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 al
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
nvd
CVE-2017-1698P4MEDIUMCVSS 5.3v7.0.0.0v8.0.0.0+6 more2017-12-27
CVE-2017-1698 [MEDIUM] CWE-200 CVE-2017-1698: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
nvd
CVE-2014-8912P4MEDIUMCVSS 5.0v6.0v6.0.0.1+30 more2015-10-28
CVE-2014-8912 [MEDIUM] CWE-284 CVE-2014-8912: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.
nvd
CVE-2014-4821P4MEDIUMCVSS 5.0v6.1.0.0v6.1.0.1+15 more2014-10-28
CVE-2014-4821 [MEDIUM] CWE-200 CVE-2014-4821: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.
nvd
CVE-2014-3056P4MEDIUMCVSS 5.0v7.0.0.0v7.0.0.1+3 more2014-07-29
CVE-2014-3056 [MEDIUM] CWE-200 CVE-2014-3056: The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows
The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive information about environment variables and JAR versions via unspecified vectors.
nvd
CVE-2017-1423P4MEDIUMCVSS 5.3v8.5.0.0v9.0.0.0+2 more2017-12-20
CVE-2017-1423 [MEDIUM] CWE-200 CVE-2017-1423: IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the We
IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.
nvd
CVE-2013-6730P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-03-04
CVE-2013-6730 [MEDIUM] CWE-264 CVE-2013-6730: IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.
nvd