CVE Vulnerabilities

CVE-2015-7472

Published: Feb 15, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Websphere_portalIbm6.1.0.0 (including)6.1.0.0 (including)
Websphere_portalIbm6.1.0.1 (including)6.1.0.1 (including)
Websphere_portalIbm6.1.0.2 (including)6.1.0.2 (including)
Websphere_portalIbm6.1.0.3 (including)6.1.0.3 (including)
Websphere_portalIbm6.1.0.4 (including)6.1.0.4 (including)
Websphere_portalIbm6.1.0.5 (including)6.1.0.5 (including)
Websphere_portalIbm6.1.0.6 (including)6.1.0.6 (including)
Websphere_portalIbm6.1.5.0 (including)6.1.5.0 (including)
Websphere_portalIbm6.1.5.1 (including)6.1.5.1 (including)
Websphere_portalIbm6.1.5.2 (including)6.1.5.2 (including)
Websphere_portalIbm6.1.5.3 (including)6.1.5.3 (including)
Websphere_portalIbm7.0.0.0 (including)7.0.0.0 (including)
Websphere_portalIbm7.0.0.1 (including)7.0.0.1 (including)
Websphere_portalIbm7.0.0.2 (including)7.0.0.2 (including)
Websphere_portalIbm8.0.0.0 (including)8.0.0.0 (including)
Websphere_portalIbm8.0.0.1 (including)8.0.0.1 (including)
Websphere_portalIbm8.5.0.0 (including)8.5.0.0 (including)

References