CVE-2014-0949: Medium severity IBM WebSphere Portal vulnerability
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0949?
CVE-2014-0949 is classified as a denial of service vulnerability, which can lead to resource exhaustion and daemon crashes.
How do I fix CVE-2014-0949?
To address CVE-2014-0949, upgrade the IBM WebSphere Portal to a fixed version that is not affected by this vulnerability.
Which versions of IBM WebSphere Portal are affected by CVE-2014-0949?
CVE-2014-0949 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12.
What kind of attack can be executed using CVE-2014-0949?
CVE-2014-0949 can be exploited through crafted web requests that cause denial of service by exhausting system resources.
Is there a workaround for CVE-2014-0949?
There are no specified workarounds for CVE-2014-0949; the best course of action is to apply the applicable software updates.