Vulnerabilities > CVE-2015-1943 - Resource Management Errors vulnerability in IBM Websphere Portal

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
ibm
CWE-399
nessus

Summary

IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyCGI abuses
    NASL idWEBSPHERE_PORTAL_6_1_0_6_CF27.NASL
    descriptionThe version of IBM WebSphere Portal installed on the remote host is 6.1.0.x prior 6.1.0.6 CF27. It is, therefore, affected by multiple vulnerabilities : - A cross-site scripting vulnerability exists in the
    last seen2020-06-01
    modified2020-06-02
    plugin id78739
    published2014-10-30
    reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/78739
    titleIBM WebSphere Portal 6.1.0.x < 6.1.0.6 CF27 Multiple Vulnerabilities
  • NASL familyCGI abuses
    NASL idWEBSPHERE_PORTAL_8_5_0_0_CF06.NASL
    descriptionThe version of IBM WebSphere Portal installed on the remote host is 8.5.0 prior to 8.5.0 CF06. It is, therefore, affected by multiple vulnerabilities : - An buffer overflow flaw exists in the Outside In Filters subcomponent due to
    last seen2020-06-01
    modified2020-06-02
    plugin id83872
    published2015-05-28
    reporterThis script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/83872
    titleIBM WebSphere Portal 8.5.0 < 8.5.0 CF06 Multiple Vulnerabilities
  • NASL familyCGI abuses
    NASL idWEBSPHERE_PORTAL_6_1_5_3_CF27.NASL
    descriptionThe version of IBM WebSphere Portal installed on the remote host is 6.1.5.x prior to 6.1.5.3 CF27. It is, therefore, affected by multiple vulnerabilities : - A cross-site scripting vulnerability exists in the
    last seen2020-06-01
    modified2020-06-02
    plugin id78740
    published2014-10-30
    reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/78740
    titleIBM WebSphere Portal 6.1.5.x < 6.1.5.3 CF27 Multiple Vulnerabilities
  • NASL familyCGI abuses
    NASL idWEBSPHERE_PORTAL_7_0_0_2_CF29.NASL
    descriptionThe version of IBM WebSphere Portal installed on the remote host is 7.0.0.x prior to 7.0.0.2 CF29. It is, therefore, affected by multiple vulnerabilities : - A remote code execution vulnerability exists in the Apache Struts ClassLoader. A remote attacker can exploit this issue by manipulating the
    last seen2020-06-01
    modified2020-06-02
    plugin id79691
    published2014-12-03
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/79691
    titleIBM WebSphere Portal 7.0.0.x < 7.0.0.2 CF29 Multiple Vulnerabilities