6.8

CVE-2014-0954

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.

Data is provided by the National Vulnerability Database (NVD)
IbmWebsphere Portal Version6.1.0.0
IbmWebsphere Portal Version6.1.0.1
IbmWebsphere Portal Version6.1.0.2
IbmWebsphere Portal Version6.1.0.3
IbmWebsphere Portal Version6.1.0.4
IbmWebsphere Portal Version6.1.0.5
IbmWebsphere Portal Version6.1.0.6
IbmWebsphere Portal Version6.1.0.6 Updatecf27
IbmWebsphere Portal Version6.1.5.0
IbmWebsphere Portal Version6.1.5.1
IbmWebsphere Portal Version6.1.5.2
IbmWebsphere Portal Version6.1.5.3
IbmWebsphere Portal Version6.1.5.3 Updatecf27
IbmWebsphere Portal Version7.0.0.0
IbmWebsphere Portal Version7.0.0.0 Updatecf001
IbmWebsphere Portal Version7.0.0.1
IbmWebsphere Portal Version7.0.0.1 Updatecf002
IbmWebsphere Portal Version7.0.0.1 Updatecf003
IbmWebsphere Portal Version7.0.0.1 Updatecf004
IbmWebsphere Portal Version7.0.0.1 Updatecf005
IbmWebsphere Portal Version7.0.0.1 Updatecf006
IbmWebsphere Portal Version7.0.0.1 Updatecf007
IbmWebsphere Portal Version7.0.0.1 Updatecf008
IbmWebsphere Portal Version7.0.0.1 Updatecf009
IbmWebsphere Portal Version7.0.0.1 Updatecf010
IbmWebsphere Portal Version7.0.0.1 Updatecf019
IbmWebsphere Portal Version7.0.0.2
IbmWebsphere Portal Version7.0.0.2 Updatecf011
IbmWebsphere Portal Version7.0.0.2 Updatecf012
IbmWebsphere Portal Version7.0.0.2 Updatecf013
IbmWebsphere Portal Version7.0.0.2 Updatecf014
IbmWebsphere Portal Version7.0.0.2 Updatecf015
IbmWebsphere Portal Version7.0.0.2 Updatecf016
IbmWebsphere Portal Version7.0.0.2 Updatecf017
IbmWebsphere Portal Version7.0.0.2 Updatecf018
IbmWebsphere Portal Version7.0.0.2 Updatecf019
IbmWebsphere Portal Version7.0.0.2 Updatecf020
IbmWebsphere Portal Version7.0.0.2 Updatecf021
IbmWebsphere Portal Version7.0.0.2 Updatecf022
IbmWebsphere Portal Version7.0.0.2 Updatecf23
IbmWebsphere Portal Version7.0.0.2 Updatecf24
IbmWebsphere Portal Version7.0.0.2 Updatecf25
IbmWebsphere Portal Version7.0.0.2 Updatecf26
IbmWebsphere Portal Version7.0.0.2 Updatecf27
IbmWebsphere Portal Version8.0.0.0
IbmWebsphere Portal Version8.0.0.0 Updatecf01
IbmWebsphere Portal Version8.0.0.0 Updatecf02
IbmWebsphere Portal Version8.0.0.0 Updatecf03
IbmWebsphere Portal Version8.0.0.0 Updatecf04
IbmWebsphere Portal Version8.0.0.0 Updatecf05
IbmWebsphere Portal Version8.0.0.1
IbmWebsphere Portal Version8.0.0.1 Updatecf04
IbmWebsphere Portal Version8.0.0.1 Updatecf05
IbmWebsphere Portal Version8.0.0.1 Updatecf07
IbmWebsphere Portal Version8.0.0.1 Updatecf08
IbmWebsphere Portal Version8.0.0.1 Updatecf09
IbmWebsphere Portal Version8.0.0.1 Updatecf10
IbmWebsphere Portal Version8.0.0.1 Updatecf11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.458
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.