Description
IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.
References (3)
Core 3
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI28699
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98567
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21692107
Scores
EPSS
0.0158
EPSS Percentile
73.0%
Details
Status
published
Products (3)
ibm/websphere_portal
8.0.0.0
ibm/websphere_portal
8.0.0.1
ibm/websphere_portal
8.5.0.0
Published
Dec 19, 2014
Tracked Since
Feb 18, 2026