Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.810734
Kategorie:Web application abuses
Titel:IBM WebSphere Portal Sensitive Information Disclosure Vulnerability(swg21963226)
Zusammenfassung:IBM Websphere Portal is prone to sensitive information Disclosure vulnerability.
Beschreibung:Summary:
IBM Websphere Portal is prone to sensitive information Disclosure vulnerability.

Vulnerability Insight:
The flaw is due to failure to restrict access
to resources located within web applications. An attacker could exploit this
vulnerability to obtain configuration data and other sensitive information.

Vulnerability Impact:
Successful exploitation will allow a remote
attacker to obtain view configuration data and other potentially sensitive
information on the target system.

Affected Software/OS:
IBM WebSphere Portal versions 6.1.0 before 6.1.0.6 CF27,
IBM WebSphere Portal versions 6.1.5 before 6.1.5.3 CF27,
IBM WebSphere Portal versions 7.0.0 before 7.0.0.2 CF29,
IBM WebSphere Portal versions 8.0.0 before 8.0.0.1 CF19, and
IBM WebSphere Portal versions 8.5.0 before CF08 .

Solution:
Upgrade to IBM WebSphere Portal
Fix Pack 6.1.0.6 with Cumulative Fix 27 (CF27).Fix Pack 6.1.5.3 with
Cumulative Fix 27 (CF27), Upgrade to Fix Pack 7.0.0.2 with Cumulative
Fix 30 (CF30), Upgrade to Fix Pack 8.0.0.1 with Cumulative Fix 19 (CF18),
8.5.0 Cumulative Fix 08 (CF08) or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-8912
AIX APAR: PI47714
http://www-01.ibm.com/support/docview.wss?uid=swg1PI47714
http://www.securitytracker.com/id/1033988
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.