Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.810734
Category:Web application abuses
Title:IBM WebSphere Portal Sensitive Information Disclosure Vulnerability (swg21963226)
Summary:IBM Websphere Portal is prone to sensitive information Disclosure vulnerability.
Description:Summary:
IBM Websphere Portal is prone to sensitive information Disclosure vulnerability.

Vulnerability Insight:
The flaw is due to failure to restrict access
to resources located within web applications. An attacker could exploit this
vulnerability to obtain configuration data and other sensitive information.

Vulnerability Impact:
Successful exploitation will allow a remote
attacker to obtain view configuration data and other potentially sensitive
information on the target system.

Affected Software/OS:
IBM WebSphere Portal versions 6.1.0 before 6.1.0.6 CF27,
IBM WebSphere Portal versions 6.1.5 before 6.1.5.3 CF27,
IBM WebSphere Portal versions 7.0.0 before 7.0.0.2 CF29,
IBM WebSphere Portal versions 8.0.0 before 8.0.0.1 CF19, and
IBM WebSphere Portal versions 8.5.0 before CF08.

Solution:
Upgrade to IBM WebSphere Portal
Fix Pack 6.1.0.6 with Cumulative Fix 27 (CF27).Fix Pack 6.1.5.3 with
Cumulative Fix 27 (CF27), Upgrade to Fix Pack 7.0.0.2 with Cumulative
Fix 30 (CF30), Upgrade to Fix Pack 8.0.0.1 with Cumulative Fix 19 (CF18),
8.5.0 Cumulative Fix 08 (CF08) or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-8912
AIX APAR: PI47714
http://www-01.ibm.com/support/docview.wss?uid=swg1PI47714
http://www.securitytracker.com/id/1033988
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.