CVE-2015-5001

MEDIUM

IBM Websphere Portal - Resource Management Error

Title source: rule
STIX 2.1

Description

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.

References (3)

Core 3
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21970176
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI49540
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034284

Scores

CVSS v3 4.3
EPSS 0.0212
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-399
Status published
Products (17)
ibm/websphere_portal 6.1.0.0
ibm/websphere_portal 6.1.0.1
ibm/websphere_portal 6.1.0.2
ibm/websphere_portal 6.1.0.3
ibm/websphere_portal 6.1.0.4
ibm/websphere_portal 6.1.0.5
ibm/websphere_portal 6.1.0.6
ibm/websphere_portal 6.1.5.0
ibm/websphere_portal 6.1.5.1
ibm/websphere_portal 6.1.5.2
... and 7 more
Published Dec 21, 2015
Tracked Since Feb 18, 2026