Description
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1035324
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21972736
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI53426
Scores
CVSS v3
7.2
EPSS
0.0167
EPSS Percentile
74.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Details
Status
published
Products (17)
ibm/websphere_portal
6.1.0.0
ibm/websphere_portal
6.1.0.1
ibm/websphere_portal
6.1.0.2
ibm/websphere_portal
6.1.0.3
ibm/websphere_portal
6.1.0.4
ibm/websphere_portal
6.1.0.5
ibm/websphere_portal
6.1.0.6
ibm/websphere_portal
6.1.5.0
ibm/websphere_portal
6.1.5.1
ibm/websphere_portal
6.1.5.2
... and 7 more
Published
Feb 15, 2016
Tracked Since
Feb 18, 2026