PT-2016-1414 · Ibm · Ibm Websphere Portal

Publicado

2016-02-15

·

Atualizado

2016-12-03

·

CVE-2015-7472

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27 IBM WebSphere Portal versions 6.1.5 through 6.1.5.3 CF27 IBM WebSphere Portal versions 7.0.0 through 7.0.0.2 CF29 IBM WebSphere Portal version 8.0.0 before 8.0.0.1 CF20 IBM WebSphere Portal version 8.5.0 before CF10
Description The issue exists due to the lack of measures to neutralize special elements in LDAP requests, allowing for LDAP injection. This can enable a remote attacker to read data or modify it.
Recommendations For versions 6.1.0 through 6.1.0.6 CF27, update to a version after 6.1.0.6 CF27. For versions 6.1.5 through 6.1.5.3 CF27, update to a version after 6.1.5.3 CF27. For versions 7.0.0 through 7.0.0.2 CF29, update to a version after 7.0.0.2 CF29. For version 8.0.0 before 8.0.0.1 CF20, update to 8.0.0.1 CF20 or later. For version 8.5.0 before CF10, update to CF10 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00715
CVE-2015-7472

Produtos afetados

Ibm Websphere Portal