CERT-In Vulnerability Note
CIVN-2015-0314
Multiple Vulnerabilities in IBM WebSphere Portal
Original Issue Date:December 23, 2015
Severity Rating: MEDIUM
Software Affected
- IBM WebSphere Portal 6.1, 7.0, 8.0, 8.5
Overview
Multiple vulnerabilities have been reported in the IBM WebSphere Portal which could be exploited by a remote attacker and can cause cross-site scripting and Denial of Service attacks.
Description
1. IBM WebSphere Portal cross site scripting (XSS) vulnerability
(
CVE-2015-4993
CVE-2015-4998
CVE-2015-7413
)
Multiple vulnerabilities exist in IBM WebSphere Portal due to improper validation of user-supplied input which allows remote attackers to create a specially crafted URL which once clicked by target user will cause arbitrary scripting code to be executed by the target users browser within the security context of the web site. Successful exploitation of the vulnerability allows remote attacker to access the target users cookies (including authentication cookies).
2. Denial of service Vulnerability
(
CVE-2015-5001
)
This vulnerability exists in IBM WebSphere Portal due to insufficient input validation. A remote attacker could exploit this vulnerability by uploading a specially crafted document to cause the consumption of all memory resources on the affected systems to crash resulting in a denial of service (DoS) condition.
Solution
Apply appropriate patches as mentioned in the IBM Security Bulletin
https://www-304.ibm.com/support/docview.wss?uid=swg21970176
Vendor Information
IBM
https://www-304.ibm.com/support/docview.wss?uid=swg21970176
References
Xforce
https://exchange.xforce.ibmcloud.com/vulnerabilities/105995
https://exchange.xforce.ibmcloud.com/vulnerabilities/106127
https://exchange.xforce.ibmcloud.com/vulnerabilities/106214
https://exchange.xforce.ibmcloud.com/vulnerabilities/107570
Securitytracker
http://www.securitytracker.com/id/1034284
CVE Name
CVE-2015-4993
CVE-2015-4998
CVE-2015-7413
CVE-2015-5001
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|