Improper input validation in WebSphere Portal - CVE-2016-5954

 

Improper input validation in WebSphere Portal - CVE-2016-5954

Published: September 12, 2016 / Updated: February 1, 2017


Vulnerability identifier: #VU404
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5954
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to cause denial of service.

The weakness exists in IBM WebSphere Portal  due to possibility to upload temporary files. A remote authenticated attacker can cause denial of service (DoS).

Successful exploitation of this vulnerability may result in denial of service.

Affected software

WebSphere Portal

How to mitigate CVE-2016-5954

The recommended solution is to apply Interim Fix PI67037 or a Cumulative Fix containing it as soon as practical.

For 8.5.0


For 8.0.0 through 8.0.0.1
For 7.0.0 through 7.0.0.2
For 6.1.5.0 through 6.1.5.3
For 6.1.0.0 through 6.1.0.6


External References

Related Security Bulletins