PT-2014-3971 · Ibm · Websphere Portal

Published

2014-05-22

·

Updated

2017-08-29

·

CVE-2014-0954

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27 IBM WebSphere Portal versions 6.1.5 through 6.1.5.3 CF27 IBM WebSphere Portal versions 7.0 through 7.0.0.2 CF28 IBM WebSphere Portal versions 8.0 before 8.0.0.1 CF12
Description The issue allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service via a crafted URL, due to the failure to validate JSP includes.
Recommendations For versions 6.1.0 through 6.1.0.6 CF27, update to a version that includes the necessary validation for JSP includes. For versions 6.1.5 through 6.1.5.3 CF27, update to a version that includes the necessary validation for JSP includes. For versions 7.0 through 7.0.0.2 CF28, update to a version that includes the necessary validation for JSP includes. For versions 8.0 before 8.0.0.1 CF12, update to version 8.0.0.1 CF12 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0954

Affected Products

Websphere Portal