VulnerabilityModified
CVE-2016-5954
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.
MEDIUM 6.5EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/websphere portal
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI67037Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg21989993Patch, Vendor Advisory
- http://www.securityfocus.com/bid/93017
- http://www.securitytracker.com/id/1036762
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI67037Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg21989993Patch, Vendor Advisory
- http://www.securityfocus.com/bid/93017
- http://www.securitytracker.com/id/1036762
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.