PT-2016-1414 · Ibm · Ibm Websphere Portal

Published

2016-02-15

·

Updated

2016-12-03

·

CVE-2015-7472

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27 IBM WebSphere Portal versions 6.1.5 through 6.1.5.3 CF27 IBM WebSphere Portal versions 7.0.0 through 7.0.0.2 CF29 IBM WebSphere Portal version 8.0.0 before 8.0.0.1 CF20 IBM WebSphere Portal version 8.5.0 before CF10
Description The issue exists due to the lack of measures to neutralize special elements in LDAP requests, allowing for LDAP injection. This can enable a remote attacker to read data or modify it.
Recommendations For versions 6.1.0 through 6.1.0.6 CF27, update to a version after 6.1.0.6 CF27. For versions 6.1.5 through 6.1.5.3 CF27, update to a version after 6.1.5.3 CF27. For versions 7.0.0 through 7.0.0.2 CF29, update to a version after 7.0.0.2 CF29. For version 8.0.0 before 8.0.0.1 CF20, update to 8.0.0.1 CF20 or later. For version 8.5.0 before CF10, update to CF10 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00715
CVE-2015-7472

Affected Products

Ibm Websphere Portal