5
CVE-2014-8912
- EPSS 0.22%
- Veröffentlicht 28.10.2015 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@us.ibm.com
- Teams Watchlist Login
- Unerledigt Login
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Portal Version6.0
Ibm ≫ Websphere Portal Version6.0.0.1
Ibm ≫ Websphere Portal Version6.0.0.2
Ibm ≫ Websphere Portal Version6.0.0.3
Ibm ≫ Websphere Portal Version6.0.0.4
Ibm ≫ Websphere Portal Version6.0.1.0
Ibm ≫ Websphere Portal Version6.0.1.1
Ibm ≫ Websphere Portal Version6.0.1.2
Ibm ≫ Websphere Portal Version6.0.1.3
Ibm ≫ Websphere Portal Version6.0.1.4
Ibm ≫ Websphere Portal Version6.0.1.5
Ibm ≫ Websphere Portal Version6.0.1.6
Ibm ≫ Websphere Portal Version6.0.1.7
Ibm ≫ Websphere Portal Version6.1
Ibm ≫ Websphere Portal Version6.1.0
Ibm ≫ Websphere Portal Version6.1.0.0
Ibm ≫ Websphere Portal Version6.1.0.1
Ibm ≫ Websphere Portal Version6.1.0.2
Ibm ≫ Websphere Portal Version6.1.0.3
Ibm ≫ Websphere Portal Version6.1.0.4
Ibm ≫ Websphere Portal Version6.1.0.5
Ibm ≫ Websphere Portal Version6.1.0.6
Ibm ≫ Websphere Portal Version6.1.5.0
Ibm ≫ Websphere Portal Version6.1.5.1
Ibm ≫ Websphere Portal Version6.1.5.2
Ibm ≫ Websphere Portal Version6.1.5.3
Ibm ≫ Websphere Portal Version7.0.0.0
Ibm ≫ Websphere Portal Version7.0.0.1
Ibm ≫ Websphere Portal Version7.0.0.2
Ibm ≫ Websphere Portal Version8.0.0.0
Ibm ≫ Websphere Portal Version8.0.0.1
Ibm ≫ Websphere Portal Version8.5.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.441 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.