CVE-2014-6193

IBM WebSphere Portal <8.5.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF14 and 8.5.0 before CF04, when the Managed Pages setting is enabled, allows remote authenticated users to write to pages via an XML injection attack.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI28699
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98567
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21692107

Scores

EPSS 0.0158
EPSS Percentile 73.0%

Details

Status published
Products (3)
ibm/websphere_portal 8.0.0.0
ibm/websphere_portal 8.0.0.1
ibm/websphere_portal 8.5.0.0
Published Dec 19, 2014
Tracked Since Feb 18, 2026