CVE-2014-8912
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/websphere portal
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI47714
- http://www-01.ibm.com/support/docview.wss?uid=swg21963226Patch, Vendor Advisory
- http://www.securitytracker.com/id/1033988
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI47714
- http://www-01.ibm.com/support/docview.wss?uid=swg21963226Patch, Vendor Advisory
- http://www.securitytracker.com/id/1033988
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.