CVE-2013-5379
- EPSS 0.19%
- Veröffentlicht 13.11.2013 15:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.x before 7.0.0.2 CF25 and 8.x before 8.0.0.1 CF8 allows remote authenticated users to inject arbitrary web script or HTML by leveraging improper tagging functionality.
- EPSS 0.21%
- Veröffentlicht 21.08.2013 16:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serveServletsByClassnameEnabled setting.
CVE-2013-0587
- EPSS 0.27%
- Veröffentlicht 16.08.2013 01:55:15
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2) Portal 7.0.0.2, (3) Portal 8.0, or (4) PortalWeb2 ...
CVE-2013-0549
- EPSS 0.32%
- Veröffentlicht 03.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attac...
CVE-2013-2950
- EPSS 0.23%
- Veröffentlicht 03.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote au...
- EPSS 1.69%
- Veröffentlicht 30.11.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.
- EPSS 0.09%
- Veröffentlicht 03.07.2012 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.
CVE-2011-2754
- EPSS 0.24%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web scrip...
CVE-2011-2172
- EPSS 0.43%
- Veröffentlicht 26.05.2011 16:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the search center in IBM WebSphere Portal 7.0.0.1 before CF004 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 0.37%
- Veröffentlicht 26.05.2011 16:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
The implementation of OutputMediator objects in IBM WebSphere Portal 6.0.1.7, and 7.0.0.1 before CF002, allows remote authenticated users to cause a denial of service (memory consumption) via requests.