cbcvebase.

Ibm Websphere Portal vulnerabilities

126 known vulnerabilities affecting ibm/websphere_portal.

Total CVEs
126
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM95LOW15

Vulnerabilities

Page 7 of 7
CVE-2009-1008P4MEDIUMCVSS 4.4v6.0.0.0v6.0.1.0+4 more2009-04-15
CVE-2009-1008 [MEDIUM] CVE-2009-1008: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.
nvd
CVE-2009-1009P4MEDIUMCVSS 4.4v6.0.0.0v6.0.1.0+4 more2009-04-15
CVE-2009-1009 [MEDIUM] CVE-2009-1009: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
nvd
CVE-2011-2173P4MEDIUMCVSS 4.0v6.0.1.7v7.0.0.12011-05-26
CVE-2011-2173 [MEDIUM] CWE-399 CVE-2011-2173: The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF0 The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.
nvd
CVE-2014-0901P4LOWCVSS 3.5v8.0.0.0v8.0.0.12014-04-02
CVE-2014-0901 [LOW] CWE-79 CVE-2014-0901: Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connectio Cross-site scripting (XSS) vulnerability in the Social Rendering implementation in the IBM Connections integration in IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-5379P4LOWCVSS 3.5v7.0.0.0v7.0.0.1+3 more2013-11-13
CVE-2013-5379 [LOW] CWE-79 CVE-2013-5379: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x bef Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.
nvd
CVE-2015-7455P4LOWCVSS 3.1v7.0.0.0v7.0.0.1+4 more2016-02-29
CVE-2015-7455 [LOW] CWE-264 CVE-2015-7455: IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 C IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.
nvd
Ibm Websphere Portal vulnerabilities | cvebase