Ibm Websphere Portal vulnerabilities
126 known vulnerabilities affecting ibm/websphere_portal.
Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15
Vulnerabilities
Page 7 of 7
CVE-2009-1008P4MEDIUMCVSS 4.4v6.0.0.0v6.0.1.0+4 more2009-04-15
CVE-2009-1008 [MEDIUM] CVE-2009-1008: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.
nvd
CVE-2009-1009P4MEDIUMCVSS 4.4v6.0.0.0v6.0.1.0+4 more2009-04-15
CVE-2009-1009 [MEDIUM] CVE-2009-1009: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
nvd
CVE-2011-2173P4MEDIUMCVSS 4.0v6.0.1.7v7.0.0.12011-05-26
CVE-2011-2173 [MEDIUM] CWE-399 CVE-2011-2173: The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF0
The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.
nvd
CVE-2014-0901P4LOWCVSS 3.5v8.0.0.0v8.0.0.12014-04-02
CVE-2014-0901 [LOW] CWE-79 CVE-2014-0901: Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connectio
Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connections integration in IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-5379P4LOWCVSS 3.5v7.0.0.0v7.0.0.1+3 more2013-11-13
CVE-2013-5379 [LOW] CWE-79 CVE-2013-5379: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x bef
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.
nvd
CVE-2015-7455P4LOWCVSS 3.1v7.0.0.0v7.0.0.1+4 more2016-02-29
CVE-2015-7455 [LOW] CWE-264 CVE-2015-7455: IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 C
IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.
nvd
← Previous7 / 7