#VU41189 Input validation error in WebSphere Portal - CVE-2014-4808


| Updated: 2020-08-10

Vulnerability identifier: #VU41189

Vulnerability risk: Low

CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2014-4808

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
WebSphere Portal
Server applications / Application servers

Vendor: IBM Corporation

Description

The vulnerability allows a remote #AU# to read and manipulate data.

Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vectors.

Mitigation
Install update from vendor's website.

Vulnerable software versions

WebSphere Portal: 6.1.0.0 - 8.0.0.1


External links
https://secunia.com/advisories/59740
https://www.securityfocus.com/bid/70757
https://www-01.ibm.com/support/docview.wss?uid=swg1PI25993
https://www-01.ibm.com/support/docview.wss?uid=swg21684651
https://exchange.xforce.ibmcloud.com/vulnerabilities/95375


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability