Resource management error in WebSphere Portal - CVE-2015-5001

 

Resource management error in WebSphere Portal - CVE-2015-5001

Published: December 21, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40571
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5001
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform service disruption.

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.


Affected software

WebSphere Portal

How to mitigate CVE-2015-5001

Install update from vendor's website.


External References

Related Security Bulletins