Skip to main content

Vendor/product archive

ibm / websphere_portal CVEs

Beta · best-effort

128 CVEs tagged to ibm / websphere_portal1 Critical, 16 High, 96 Medium, 15 Low, 0 Unrated.

CVE-2018-1673

Published Oct 12, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1672

Published Oct 1, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a diffe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1420

Published Oct 1, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1820

Published Sep 27, 2018

IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1736

Published Sep 27, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-c…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1716

Published Sep 27, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1660

Published Sep 27, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2951

Published Jul 11, 2018

IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1445

Published Apr 17, 2018

IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1483

Published Apr 11, 2018

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1444

Published Mar 14, 2018

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1416

Published Feb 27, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1401

Published Feb 9, 2018

IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1761

Published Feb 9, 2018

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1361

Published Jan 11, 2018

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1698

Published Dec 27, 2017

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1423

Published Dec 20, 2017

IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1536

Published Dec 11, 2017

IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1577

Published Sep 28, 2017

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1189

Published Sep 7, 2017

IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1303

Published Jul 31, 2017

IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1217

Published Jul 5, 2017

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1156

Published May 5, 2017

IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1120

Published Mar 27, 2017

IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 128 CVEsPage 1 of 6