Input validation error in WebSphere Portal - CVE-2014-4808

 

Input validation error in WebSphere Portal - CVE-2014-4808

Published: October 28, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41189
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4808
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors.


Affected software

WebSphere Portal

How to mitigate CVE-2014-4808

Install update from vendor's website.


External References

Related Security Bulletins