PT-2014-7096 · Ibm · Ibm Websphere Portal

Published

2014-12-19

·

Updated

2017-09-08

·

CVE-2014-6193

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM WebSphere Portal versions 8.0.0 through 8.0.0.1 CF14 IBM WebSphere Portal versions 8.5.0 before CF04
Description The issue allows remote authenticated users to write to pages via an XML injection attack when the Managed Pages setting is enabled.
Recommendations For IBM WebSphere Portal versions 8.0.0 through 8.0.0.1 CF14, update to a version after CF14 to resolve the issue. For IBM WebSphere Portal versions 8.5.0 before CF04, apply CF04 or a later cumulative fix to address the problem. As a temporary workaround, consider disabling the Managed Pages setting until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-6193

Affected Products

Ibm Websphere Portal