Resource management error in WebSphere Portal - CVE-2014-4792

 

Resource management error in WebSphere Portal - CVE-2014-4792

Published: September 12, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41337
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4792
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to perform service disruption.

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, 8.0.0 through 8.0.0.1 CF13, and 8.5.0 before CF02 allows remote authenticated users to cause a denial of service (disk consumption) by uploading large files.


Affected software

WebSphere Portal

How to mitigate CVE-2014-4792

Install update from vendor's website.


External References

Related Security Bulletins