Vulnerability Name: | CVE-2015-7455 (CCN-108334) |
Assigned: | 2015-09-29 |
Published: | 2016-02-23 |
Updated: | 2016-03-02 |
Summary: | IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI. Appropriate Vendor Advisory Link: <a href="http://www-01.ibm.com/support/docview.wss?uid=swg21976358">HERE</a>
|
CVSS v3 Severity: | 3.1 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N) 2.7 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None | 3.1 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N) 2.7 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-264
|
Vulnerability Consequences: | Data Manipulation |
References: | Source: MITRE Type: CNA CVE-2015-7455
Source: AIXAPAR Type: UNKNOWN PI51234
Source: CONFIRM Type: UNKNOWN http://www.ibm.com/support/docview.wss?uid=swg21975358
Source: CCN Type: IBM Security Bulletin 1976358 (WebSphere Portal) Fixes available for Security Vulnerabilities in IBM WebSphere Portal
Source: XF Type: UNKNOWN ibm-websphere-cve20157455-sec-bypass(108334)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:8.0.0.1:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:8.5.0.0:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:ibm:websphere_portal:7.0:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:8.0:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:8.5:*:*:*:*:*:*:*OR cpe:/a:ibm:websphere_portal:6.1:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |