Ibm Websphere Portal vulnerabilities

126 known vulnerabilities affecting ibm/websphere_portal.

Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15

Vulnerabilities

Page 5 of 7
CVE-2014-0956MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0956 [MEDIUM] CWE-79 CVE-2014-0956: Cross-site scripting (XSS) vulnerability in googlemap.jsp in IBM WebSphere Portal 6.1.0 through 6.1. Cross-site scripting (XSS) vulnerability in googlemap.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0954MEDIUMCVSS 6.8v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0954 [MEDIUM] CWE-20 CVE-2014-0954: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.
nvd
CVE-2014-0949MEDIUMCVSS 5.0v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0949 [MEDIUM] CWE-399 CVE-2014-0949: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.
nvd
CVE-2014-0952MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0952 [MEDIUM] CWE-79 CVE-2014-0952: Cross-site scripting (XSS) vulnerability in boot_config.jsp in IBM WebSphere Portal 6.1.0 through 6. Cross-site scripting (XSS) vulnerability in boot_config.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF28, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0958MEDIUMCVSS 5.8v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0958 [MEDIUM] CVE-2014-0958: Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5. Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2014-0959MEDIUMCVSS 4.0v6.1.0.0v6.1.0.1+14 more2014-05-22
CVE-2014-0959 [MEDIUM] CWE-20 CVE-2014-0959: IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF2 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.
nvd
CVE-2014-0955MEDIUMCVSS 4.3v8.0.0.0v8.0.0.12014-05-22
CVE-2014-0955 [MEDIUM] CWE-79 CVE-2014-0955: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0 before 8.0.0.1 CF12, when Socia Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0 before 8.0.0.1 CF12, when Social Rendering in Connections integration is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0918HIGHCVSS 7.1v6.1.0.0v6.1.0.1+14 more2014-05-16
CVE-2014-0918 [HIGH] CWE-22 CVE-2014-0918: Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 th Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2014-0917MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-05-16
CVE-2014-0917 [MEDIUM] CWE-79 CVE-2014-0917: Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6 Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-0828MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-04-02
CVE-2014-0828 [MEDIUM] CWE-79 CVE-2014-0828: Cross-site scripting (XSS) vulnerability in the WCM (Web Content Manager) UI in IBM WebSphere Portal Cross-site scripting (XSS) vulnerability in the WCM (Web Content Manager) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2014-0901LOWCVSS 3.5v8.0.0.0v8.0.0.12014-04-02
CVE-2014-0901 [LOW] CWE-79 CVE-2014-0901: Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connectio Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connections integration in IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-6730MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2014-03-04
CVE-2013-6730 [MEDIUM] CWE-264 CVE-2013-6730: IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0. IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.
nvd
CVE-2013-6722MEDIUMCVSS 5.8v7.0.0.0v7.0.0.1+4 more2014-02-14
CVE-2013-6722 [MEDIUM] CVE-2013-6722: Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.0.0.1 CF09 allows remote attackers to cause a denial of service or modify data via unspecified vectors.
nvd
CVE-2013-6316MEDIUMCVSS 4.3v7.0.0.0v7.0.0.1+3 more2013-12-22
CVE-2013-6316 [MEDIUM] CWE-264 CVE-2013-6316: IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly h IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-selection changes during Taxonomy component rendering, which allows remote attackers to obtain sensitive property information in opportunistic circumstances by leveraging an error in a Web Content Manager (WCM) context processor.
nvd
CVE-2013-6328MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+14 more2013-12-22
CVE-2013-6328 [MEDIUM] CWE-79 CVE-2013-6328: Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.
nvd
CVE-2013-4012MEDIUMCVSS 4.9v8.0.0.0v8.0.0.12013-12-22
CVE-2013-4012 [MEDIUM] CWE-264 CVE-2013-4012: IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does no IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.
nvd
CVE-2013-6735MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+24 more2013-12-22
CVE-2013-6735 [MEDIUM] CWE-264 CVE-2013-6735: IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.
nvd
CVE-2013-6723MEDIUMCVSS 5.0v8.0.0.12013-12-22
CVE-2013-6723 [MEDIUM] CWE-264 CVE-2013-6723: IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.
nvd
CVE-2013-5454MEDIUMCVSS 4.3v6.0.0.0v6.0.0.1+24 more2013-11-18
CVE-2013-5454 [MEDIUM] CWE-200 CVE-2013-5454: IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7. IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.
nvd
CVE-2013-5379LOWCVSS 3.5v7.0.0.0v7.0.0.1+3 more2013-11-13
CVE-2013-5379 [LOW] CWE-79 CVE-2013-5379: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x bef Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.
nvd