Ibm Websphere Portal vulnerabilities
126 known vulnerabilities affecting ibm/websphere_portal.
Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15
Vulnerabilities
Page 3 of 7
CVE-2015-5001MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+15 more2015-12-21
CVE-2015-5001 [MEDIUM] CWE-399 CVE-2015-5001: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.
nvd
CVE-2015-4998MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2015-12-21
CVE-2015-4998 [MEDIUM] CVE-2015-4998: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
nvd
CVE-2015-7419HIGHCVSS 7.8v8.0.0.1v8.5.0.02015-11-14
CVE-2015-7419 [HIGH] CWE-399 CVE-2015-7419: IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a de
IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
nvd
CVE-2015-4997MEDIUMCVSS 6.8v8.5.0.02015-10-29
CVE-2015-4997 [MEDIUM] CWE-264 CVE-2015-4997: IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restriction
IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request.
nvd
CVE-2014-8912MEDIUMCVSS 5.0v6.0v6.0.0.1+30 more2015-10-28
CVE-2014-8912 [MEDIUM] CWE-284 CVE-2014-8912: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 C
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.
nvd
CVE-2015-1943HIGHCVSS 7.8v6.1.0.0v6.1.0.1+15 more2015-09-14
CVE-2015-1943 [HIGH] CWE-399 CVE-2015-1943: IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0
IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
nvd
CVE-2015-1917MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2015-07-14
CVE-2015-1917 [MEDIUM] CWE-79 CVE-2015-1917: Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-1887MEDIUMCVSS 5.0v7.0.0.0v7.0.0.1+4 more2015-07-14
CVE-2015-1887 [MEDIUM] CWE-200 CVE-2015-1887: IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 al
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
nvd
CVE-2015-1944LOWCVSS 3.5v8.0.0.0v8.0.0.1+1 more2015-07-14
CVE-2015-1944 [LOW] CWE-79 CVE-2015-1944: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-1899HIGHCVSS 7.8v8.5.0.02015-05-25
CVE-2015-1899 [HIGH] CWE-399 CVE-2015-1899: IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU cons
IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
nvd
CVE-2015-1921MEDIUMCVSS 6.4v8.0.0.0v8.0.0.1+1 more2015-05-25
CVE-2015-1921 [MEDIUM] CVE-2015-1921: Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
nvd
CVE-2015-1886HIGHCVSS 7.8v6.1.0.0v6.1.0.1+15 more2015-04-27
CVE-2015-1886 [HIGH] CWE-399 CVE-2015-1886: The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1
The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
nvd
CVE-2015-1908MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+15 more2015-04-27
CVE-2015-1908 [MEDIUM] CWE-79 CVE-2015-1908: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6214MEDIUMCVSS 6.8v8.0.0.0v8.0.0.1+1 more2015-03-13
CVE-2014-6214 [MEDIUM] CWE-352 CVE-2014-6214: Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 a
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2015-0177LOWCVSS 3.5v8.5.0.02015-03-13
CVE-2015-0177 [LOW] CWE-79 CVE-2015-0177: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF05 allows remote aut
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-0139LOWCVSS 3.5v8.0.0.0v8.0.0.1+1 more2015-03-13
CVE-2015-0139 [LOW] CWE-79 CVE-2015-0139: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-8909LOWCVSS 3.5v6.1.0.0v6.1.0.1+12 more2015-02-13
CVE-2014-8909 [LOW] CWE-79 CVE-2014-8909: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6193MEDIUMCVSS 4.9v8.0.0.0v8.0.0.1+1 more2014-12-19
CVE-2014-6193 [MEDIUM] CVE-2014-6193: IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages settin
IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.
nvd
CVE-2014-8902MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+15 more2014-12-19
CVE-2014-8902 [MEDIUM] CWE-79 CVE-2014-8902: Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6
Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6171MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+15 more2014-12-19
CVE-2014-6171 [MEDIUM] CWE-79 CVE-2014-6171: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd