Vulnerabilities > Jasig

DATE CVE VULNERABILITY TITLE RISK
2014-05-29 CVE-2014-3417 Permissions, Privileges, and Access Controls vulnerability in Jasig Uportal 4.0.13
uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet.
network
low complexity
jasig CWE-264
6.5
2014-05-29 CVE-2014-3416 Permissions, Privileges, and Access Controls vulnerability in Jasig Uportal 4.0.13
uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet.
network
low complexity
jasig CWE-264
6.5