7.5
CVE-2014-3055
- EPSS 1.95%
- Veröffentlicht 29.07.2014 20:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Portal Version 7.0.0.0
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf003
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf004
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf005
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf006
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf007
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf008
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf009
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf010
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf019
Ibm ≫ Websphere Portal Version 7.0.0.2
Ibm ≫ Websphere Portal Version 7.0.0.2 Update -
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf011
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf012
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf013
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf014
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf015
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf016
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf017
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf018
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf019
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf020
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf021
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf022
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf23
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf24
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf25
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf26
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf27
Ibm ≫ Websphere Portal Version 8.0.0.0
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf01
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf02
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf03
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf04
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf05
Ibm ≫ Websphere Portal Version 8.0.0.1
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf04
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf05
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf06
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf07
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf08
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf09
Ibm ≫ Websphere Portal Version 8.0.0.1 Update cf12
Ibm ≫ Websphere Portal Unified Task List Portlet Version 6.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.95% | 0.776 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
http://secunia.com/advisories/60499
http://www-01.ibm.com/support/docview.wss?uid=swg1PI18909
http://www-01.ibm.com/support/docview.wss?uid=swg21677032
https://exchange.xforce.ibmcloud.com/vulnerabilities/93529