7.5

CVE-2014-3055

SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
IbmWebsphere Portal Version7.0.0.0
IbmWebsphere Portal Version7.0.0.1 Updatecf003
IbmWebsphere Portal Version7.0.0.1 Updatecf004
IbmWebsphere Portal Version7.0.0.1 Updatecf005
IbmWebsphere Portal Version7.0.0.1 Updatecf006
IbmWebsphere Portal Version7.0.0.1 Updatecf007
IbmWebsphere Portal Version7.0.0.1 Updatecf008
IbmWebsphere Portal Version7.0.0.1 Updatecf009
IbmWebsphere Portal Version7.0.0.1 Updatecf010
IbmWebsphere Portal Version7.0.0.1 Updatecf019
IbmWebsphere Portal Version7.0.0.2
IbmWebsphere Portal Version7.0.0.2 Update-
IbmWebsphere Portal Version7.0.0.2 Updatecf011
IbmWebsphere Portal Version7.0.0.2 Updatecf012
IbmWebsphere Portal Version7.0.0.2 Updatecf013
IbmWebsphere Portal Version7.0.0.2 Updatecf014
IbmWebsphere Portal Version7.0.0.2 Updatecf015
IbmWebsphere Portal Version7.0.0.2 Updatecf016
IbmWebsphere Portal Version7.0.0.2 Updatecf017
IbmWebsphere Portal Version7.0.0.2 Updatecf018
IbmWebsphere Portal Version7.0.0.2 Updatecf019
IbmWebsphere Portal Version7.0.0.2 Updatecf020
IbmWebsphere Portal Version7.0.0.2 Updatecf021
IbmWebsphere Portal Version7.0.0.2 Updatecf022
IbmWebsphere Portal Version7.0.0.2 Updatecf23
IbmWebsphere Portal Version7.0.0.2 Updatecf24
IbmWebsphere Portal Version7.0.0.2 Updatecf25
IbmWebsphere Portal Version7.0.0.2 Updatecf26
IbmWebsphere Portal Version7.0.0.2 Updatecf27
IbmWebsphere Portal Version8.0.0.0
IbmWebsphere Portal Version8.0.0.0 Updatecf01
IbmWebsphere Portal Version8.0.0.0 Updatecf02
IbmWebsphere Portal Version8.0.0.0 Updatecf03
IbmWebsphere Portal Version8.0.0.0 Updatecf04
IbmWebsphere Portal Version8.0.0.0 Updatecf05
IbmWebsphere Portal Version8.0.0.1
IbmWebsphere Portal Version8.0.0.1 Updatecf04
IbmWebsphere Portal Version8.0.0.1 Updatecf05
IbmWebsphere Portal Version8.0.0.1 Updatecf06
IbmWebsphere Portal Version8.0.0.1 Updatecf07
IbmWebsphere Portal Version8.0.0.1 Updatecf08
IbmWebsphere Portal Version8.0.0.1 Updatecf09
IbmWebsphere Portal Version8.0.0.1 Updatecf12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.495
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.