Ibm Websphere Portal vulnerabilities
126 known vulnerabilities affecting ibm/websphere_portal.
Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15
Vulnerabilities
Page 6 of 7
CVE-2013-5378LOWCVSS 3.5v8.0.0.0v8.0.0.12013-11-13
CVE-2013-5378 [LOW] CWE-79 CVE-2013-5378: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x before 8.0.0.1 CF8 allows remot
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging incorrect IBM Connections integration.
nvd
CVE-2013-3016MEDIUMCVSS 5.0v6.1.0.0v7.0.0.0+2 more2013-08-21
CVE-2013-3016 [MEDIUM] CWE-264 CVE-2013-3016: IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a cr
IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serveServletsByClassnameEnabled setting.
nvd
CVE-2013-0587MEDIUMCVSS 4.3≤ 8.0.0.1v5.1.0.0+29 more2013-08-16
CVE-2013-0587 [MEDIUM] CWE-79 CVE-2013-0587: Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allo
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2) Portal 7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 theme.
nvd
CVE-2013-0549MEDIUMCVSS 4.3v7.0.0.0v7.0.0.1+4 more2013-06-03
CVE-2013-0549 [MEDIUM] CWE-79 CVE-2013-0549: Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in
Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2013-2950LOWCVSS 3.5v8.0v8.0.0.0+9 more2013-06-03
CVE-2013-2950 [LOW] CWE-94 CVE-2013-2950: CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1
CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecif
nvd
CVE-2012-4834MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+1 more2012-11-30
CVE-2012-4834 [MEDIUM] CWE-22 CVE-2012-4834: Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal
Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.
nvd
CVE-2012-2181MEDIUMCVSS 5.0v7.0.0.1v7.0.0.2+1 more2012-07-03
CVE-2012-2181 [MEDIUM] CWE-22 CVE-2012-2181: Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 bef
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.
nvd
CVE-2011-2754MEDIUMCVSS 4.3v7.0.0.0v7.0.0.12011-07-17
CVE-2011-2754 [MEDIUM] CWE-79 CVE-2011-2754: Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphe
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-2173MEDIUMCVSS 4.0v6.0.1.7v7.0.0.12011-05-26
CVE-2011-2173 [MEDIUM] CWE-399 CVE-2011-2173: The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF0
The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.
nvd
CVE-2011-2172MEDIUMCVSS 4.3v7.0.0.12011-05-26
CVE-2011-2172 [MEDIUM] CWE-79 CVE-2011-2172: Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before
Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-0679MEDIUMCVSS 5.0v6.0.1.1v6.0.1.2+11 more2011-01-28
CVE-2011-0679 [MEDIUM] CWE-200 CVE-2011-0679: IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and
IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensitive information via a "modified message."
nvd
CVE-2010-4219MEDIUMCVSS 4.3v6.1.0.12010-11-09
CVE-2010-4219 [MEDIUM] CWE-79 CVE-2010-4219: Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 al
Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
nvd
CVE-2010-1348HIGHCVSS 7.5v6.0.1.1v6.1.0.0+2 more2010-04-12
CVE-2010-1348 [HIGH] CVE-2010-1348: Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6
Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors.
nvd
CVE-2010-0714MEDIUMCVSS 4.3PoCv5.1.0.0v5.1.0.1+22 more2010-02-26
CVE-2010-0714 [MEDIUM] CWE-79 CVE-2010-0714: Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content
Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for Web
nvd
CVE-2010-0715MEDIUMCVSS 6.8v5.1.0.0v5.1.0.1+22 more2010-02-26
CVE-2010-0715 [MEDIUM] CVE-2010-0715: Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (
Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allow
nvd
CVE-2010-0704MEDIUMCVSS 4.3v6.0.1.52010-02-25
CVE-2010-0704 [MEDIUM] CWE-79 CVE-2010-0704: Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp60
Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field.
nvd
CVE-2009-4153HIGHCVSS 7.5v6.1.0.0v6.1.0.1+1 more2009-12-02
CVE-2009-4153 [HIGH] CVE-2009-4153: Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 ha
Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and attack vectors, related to the work directory.
nvd
CVE-2009-4152MEDIUMCVSS 4.3v6.1.0.0v6.1.0.1+1 more2009-12-02
CVE-2009-4152 [MEDIUM] CWE-79 CVE-2009-4152: Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.
Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote attackers to inject arbitrary web script or HTML via the people picker tag.
nvd
CVE-2009-0899MEDIUMCVSS 4.3≥ 5.1, < 6.0.0.02009-06-03
CVE-2009-0899 [MEDIUM] CWE-264 CVE-2009-0899: IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere P
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which a
nvd
CVE-2009-1010MEDIUMCVSS 4.4v6.0.0.0v6.0.1.0+4 more2009-04-15
CVE-2009-1010 [MEDIUM] CVE-2009-1010: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.
nvd