CVE-2015-7455

LOW

IBM WebSphere Portal <8.5.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.

References (2)

Core 2
Core References
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21975358
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI51234

Scores

CVSS v3 3.1
EPSS 0.0068
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-264
Status published
Products (6)
ibm/websphere_portal 7.0.0.0
ibm/websphere_portal 7.0.0.1
ibm/websphere_portal 7.0.0.2
ibm/websphere_portal 8.0.0.0
ibm/websphere_portal 8.0.0.1
ibm/websphere_portal 8.5.0.0
Published Feb 29, 2016
Tracked Since Feb 18, 2026