7.5
CVE-2014-3055
- EPSS 0.29%
- Published 29.07.2014 20:55:08
- Last modified 12.04.2025 10:46:40
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Websphere Portal Version7.0.0.0
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf003
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf004
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf005
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf006
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf007
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf008
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf009
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf010
Ibm ≫ Websphere Portal Version7.0.0.1 Updatecf019
Ibm ≫ Websphere Portal Version7.0.0.2
Ibm ≫ Websphere Portal Version7.0.0.2 Update-
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf011
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf012
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf013
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf014
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf015
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf016
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf017
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf018
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf019
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf020
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf021
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf022
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf23
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf24
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf25
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf26
Ibm ≫ Websphere Portal Version7.0.0.2 Updatecf27
Ibm ≫ Websphere Portal Version8.0.0.0
Ibm ≫ Websphere Portal Version8.0.0.0 Updatecf01
Ibm ≫ Websphere Portal Version8.0.0.0 Updatecf02
Ibm ≫ Websphere Portal Version8.0.0.0 Updatecf03
Ibm ≫ Websphere Portal Version8.0.0.0 Updatecf04
Ibm ≫ Websphere Portal Version8.0.0.0 Updatecf05
Ibm ≫ Websphere Portal Version8.0.0.1
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf04
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf05
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf06
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf07
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf08
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf09
Ibm ≫ Websphere Portal Version8.0.0.1 Updatecf12
Ibm ≫ Websphere Portal Unified Task List Portlet Version6.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.29% | 0.495 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.