CVE-2014-0954: Input Validation
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0954?
CVE-2014-0954 is rated as a medium to high severity vulnerability due to potential unauthorized access to sensitive information.
How do I fix CVE-2014-0954?
To fix CVE-2014-0954, apply the latest security patches provided by IBM for WebSphere Portal installations.
What versions are affected by CVE-2014-0954?
CVE-2014-0954 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12.
What type of attacks can CVE-2014-0954 enable?
CVE-2014-0954 can allow remote attackers to obtain sensitive information and bypass request-dispatcher access restrictions.
Is there a workaround for CVE-2014-0954 until I can patch?
Implementing strict input validation and access controls can serve as a temporary workaround for CVE-2014-0954.