Vulnerability identifier: #VU41189
Vulnerability risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-20
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
WebSphere Portal
Server applications /
Application servers
Vendor: IBM Corporation
Description
The vulnerability allows a remote #AU# to read and manipulate data.
Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors.
Mitigation
Install update from vendor's website.
Vulnerable software versions
WebSphere Portal: 6.1.0.0 - 8.0.0.1
External links
https://secunia.com/advisories/59740
https://www.securityfocus.com/bid/70757
https://www-01.ibm.com/support/docview.wss?uid=swg1PI25993
https://www-01.ibm.com/support/docview.wss?uid=swg21684651
https://exchange.xforce.ibmcloud.com/vulnerabilities/95375
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.