Lucene search

K
cvelistIbmCVELIST:CVE-2014-0954
HistoryMay 22, 2014 - 10:00 a.m.

CVE-2014-0954

2014-05-2210:00:00
ibm
www.cve.org
5

AI Score

6.5

Confidence

High

EPSS

0.005

Percentile

76.8%

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.

AI Score

6.5

Confidence

High

EPSS

0.005

Percentile

76.8%

Related for CVELIST:CVE-2014-0954