cbcvebase.

Ibm Websphere Portal vulnerabilities

126 known vulnerabilities affecting ibm/websphere_portal.

Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15

Vulnerabilities

Page 4 of 7
CVE-2010-0715P4MEDIUMCVSS 6.8v5.1.0.0v5.1.0.1+22 more2010-02-26
CVE-2010-0715 [MEDIUM] CVE-2010-0715: Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management ( Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allow
nvd
CVE-2011-0679P4MEDIUMCVSS 5.0v6.0.1.1v6.0.1.2+11 more2011-01-28
CVE-2011-0679 [MEDIUM] CWE-200 CVE-2011-0679: IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
nvd
CVE-2017-1189P4MEDIUMCVSS 6.1v6.1.0.0v6.1.0.1+15 more2017-09-07
CVE-2017-1189 [MEDIUM] CWE-79 CVE-2017-1189: IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.
nvd
CVE-2015-7457P4MEDIUMCVSS 6.1v8.0.0.0v8.0.0.1+1 more2016-02-29
CVE-2015-7457 [MEDIUM] CWE-79 CVE-2015-7457: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2016-8922P4MEDIUMCVSS 6.1v8.0v8.52017-02-01
CVE-2016-8922 [MEDIUM] CWE-79 CVE-2016-8922: Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi Exphox WebRadar is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2016-2925P4MEDIUMCVSS 5.4v6.1.0.0v6.1.0.1+15 more2016-08-08
CVE-2016-2925 [MEDIUM] CWE-79 CVE-2016-2925: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5 Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2018-1660P4MEDIUMCVSS 5.4v7.0.0.0v7.0.0.1+9 more2018-09-27
CVE-2018-1660 [MEDIUM] CWE-79 CVE-2018-1660: IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerabilit IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144886.
nvd
CVE-2018-1820P4MEDIUMCVSS 5.4v8.0.0.0v8.0.0.1+5 more2018-09-27
CVE-2018-1820 [MEDIUM] CWE-79 CVE-2018-1820: IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability all IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150096.
nvd
CVE-2018-1444P4MEDIUMCVSS 5.4v8.5.0.0v9.0.0.0+2 more2018-03-14
CVE-2018-1444 [MEDIUM] CWE-79 CVE-2018-1444: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows us IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906.
nvd
CVE-2018-1445P4MEDIUMCVSS 5.4≥ 8.0.0.0, ≤ 8.0.0.1v8.5+3 more2018-04-17
CVE-2018-1445 [MEDIUM] CWE-79 CVE-2018-1445: IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139907.
nvd
CVE-2017-1536P4MEDIUMCVSS 5.4v7.0v8.0+2 more2017-12-11
CVE-2017-1536 [MEDIUM] CWE-79 CVE-2017-1536: IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross- IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130733.
nvd
CVE-2015-1921P4MEDIUMCVSS 6.4v8.0.0.0v8.0.0.1+1 more2015-05-25
CVE-2015-1921 [MEDIUM] CVE-2015-1921: Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 Open redirect vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
nvd
CVE-2016-0209P4MEDIUMCVSS 6.1v8.5.0.02016-01-27
CVE-2016-0209 [MEDIUM] CWE-79 CVE-2016-0209: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote att Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-6723P4MEDIUMCVSS 5.0v8.0.0.12013-12-22
CVE-2013-6723 [MEDIUM] CWE-264 CVE-2013-6723: IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.
nvd
CVE-2015-7491P4MEDIUMCVSS 5.4v8.0.0.0v8.0.0.1+1 more2016-02-29
CVE-2015-7491 [MEDIUM] CWE-79 CVE-2015-7491: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-3054P4MEDIUMCVSS 5.8v7.0.0.0v7.0.0.1+3 more2014-07-29
CVE-2014-3054 [MEDIUM] CVE-2014-3054: Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Port Multiple open redirect vulnerabilities in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2014-0958P4MEDIUMCVSS 5.8v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0958 [MEDIUM] CVE-2014-0958: Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5. Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2014-0949P4MEDIUMCVSS 5.0v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0949 [MEDIUM] CWE-399 CVE-2014-0949: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.
nvd
CVE-2015-1917P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2015-07-14
CVE-2015-1917 [MEDIUM] CWE-79 CVE-2015-1917: Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-1908P4MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+15 more2015-04-27
CVE-2015-1908 [MEDIUM] CWE-79 CVE-2015-1908: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 t Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
Ibm Websphere Portal vulnerabilities | cvebase