CVE Vulnerabilities

CVE-2015-7472

Published: Feb 15, 2016 | Modified: Dec 03, 2016
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Websphere_portal Ibm 6.1.0.0 (including) 6.1.0.0 (including)
Websphere_portal Ibm 6.1.0.1 (including) 6.1.0.1 (including)
Websphere_portal Ibm 6.1.0.2 (including) 6.1.0.2 (including)
Websphere_portal Ibm 6.1.0.3 (including) 6.1.0.3 (including)
Websphere_portal Ibm 6.1.0.4 (including) 6.1.0.4 (including)
Websphere_portal Ibm 6.1.0.5 (including) 6.1.0.5 (including)
Websphere_portal Ibm 6.1.0.6 (including) 6.1.0.6 (including)
Websphere_portal Ibm 6.1.5.0 (including) 6.1.5.0 (including)
Websphere_portal Ibm 6.1.5.1 (including) 6.1.5.1 (including)
Websphere_portal Ibm 6.1.5.2 (including) 6.1.5.2 (including)
Websphere_portal Ibm 6.1.5.3 (including) 6.1.5.3 (including)
Websphere_portal Ibm 7.0.0.0 (including) 7.0.0.0 (including)
Websphere_portal Ibm 7.0.0.1 (including) 7.0.0.1 (including)
Websphere_portal Ibm 7.0.0.2 (including) 7.0.0.2 (including)
Websphere_portal Ibm 8.0.0.0 (including) 8.0.0.0 (including)
Websphere_portal Ibm 8.0.0.1 (including) 8.0.0.1 (including)
Websphere_portal Ibm 8.5.0.0 (including) 8.5.0.0 (including)

References