Ibm Websphere Portal vulnerabilities
126 known vulnerabilities affecting ibm/websphere_portal.
Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15
Vulnerabilities
Page 4 of 7
CVE-2010-0715P4MEDIUMCVSS 6.8v5.1.0.0v5.1.0.1+22 more2010-02-26
CVE-2010-0715 [MEDIUM] CVE-2010-0715: Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (
Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allow
nvd
CVE-2011-0679P4MEDIUMCVSS 5.0v6.0.1.1v6.0.1.2+11 more2011-01-28
CVE-2011-0679 [MEDIUM] CWE-200 CVE-2011-0679: IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and
IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
nvd
CVE-2017-1189P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2017-09-07
CVE-2017-1189 [MEDIUM] CWE-79 CVE-2017-1189: IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting
IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.
nvd
CVE-2015-7457P4MEDIUMCVSS 6.1v8.0.0.0v8.0.0.1+1 more2016-02-29
CVE-2015-7457 [MEDIUM] CWE-79 CVE-2015-7457: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-8922P4MEDIUMCVSS 6.1v8.0v8.52017-02-01
CVE-2016-8922 [MEDIUM] CWE-79 CVE-2016-8922: Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi
Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-2925P4MEDIUMCVSS 5.4v6.1.0.0v6.1.0.1+15 more2016-08-08
CVE-2016-2925 [MEDIUM] CWE-79 CVE-2016-2925: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2018-1660P4MEDIUMCVSS 5.4v7.0.0.0v7.0.0.1+9 more2018-09-27
CVE-2018-1660 [MEDIUM] CWE-79 CVE-2018-1660: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.
nvd
CVE-2018-1820P4MEDIUMCVSS 5.4v8.0.0.0v8.0.0.1+5 more2018-09-27
CVE-2018-1820 [MEDIUM] CWE-79 CVE-2018-1820: IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability all
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.
nvd
CVE-2018-1444P4MEDIUMCVSS 5.4v8.5.0.0v9.0.0.0+2 more2018-03-14
CVE-2018-1444 [MEDIUM] CWE-79 CVE-2018-1444: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906.
nvd
CVE-2018-1445P4MEDIUMCVSS 5.4≥ 8.0.0.0, ≤ 8.0.0.1v8.5+3 more2018-04-17
CVE-2018-1445 [MEDIUM] CWE-79 CVE-2018-1445: IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This
IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.
nvd
CVE-2017-1536P4MEDIUMCVSS 5.4v7.0v8.0+2 more2017-12-11
CVE-2017-1536 [MEDIUM] CWE-79 CVE-2017-1536: IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-
IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130733.
nvd
CVE-2015-1921P4MEDIUMCVSS 6.4v8.0.0.0v8.0.0.1+1 more2015-05-25
CVE-2015-1921 [MEDIUM] CVE-2015-1921: Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06
Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
nvd
CVE-2016-0209P4MEDIUMCVSS 6.1v8.5.0.02016-01-27
CVE-2016-0209 [MEDIUM] CWE-79 CVE-2016-0209: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote att
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-6723P4MEDIUMCVSS 5.0v8.0.0.12013-12-22
CVE-2013-6723 [MEDIUM] CWE-264 CVE-2013-6723: IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web
IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.
nvd
CVE-2015-7491P4MEDIUMCVSS 5.4v8.0.0.0v8.0.0.1+1 more2016-02-29
CVE-2015-7491 [MEDIUM] CWE-79 CVE-2015-7491: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-3054P4MEDIUMCVSS 5.8v7.0.0.0v7.0.0.1+3 more2014-07-29
CVE-2014-3054 [MEDIUM] CVE-2014-3054: Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Port
Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2014-0958P4MEDIUMCVSS 5.8v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0958 [MEDIUM] CVE-2014-0958: Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.
Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2014-0949P4MEDIUMCVSS 5.0v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0949 [MEDIUM] CWE-399 CVE-2014-0949: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.
nvd
CVE-2015-1917P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2015-07-14
CVE-2015-1917 [MEDIUM] CWE-79 CVE-2015-1917: Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-1908P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+15 more2015-04-27
CVE-2015-1908 [MEDIUM] CWE-79 CVE-2015-1908: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd