First published: Thu May 22 2014(Updated: )
Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =6.1.0.0 | |
IBM WebSphere Portal | =6.1.0.1 | |
IBM WebSphere Portal | =6.1.0.2 | |
IBM WebSphere Portal | =6.1.0.3 | |
IBM WebSphere Portal | =6.1.0.4 | |
IBM WebSphere Portal | =6.1.0.5 | |
IBM WebSphere Portal | =6.1.0.6 | |
IBM WebSphere Portal | =6.1.0.6-cf27 | |
IBM WebSphere Portal | =6.1.5.0 | |
IBM WebSphere Portal | =6.1.5.1 | |
IBM WebSphere Portal | =6.1.5.2 | |
IBM WebSphere Portal | =6.1.5.3 | |
IBM WebSphere Portal | =6.1.5.3-cf27 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.0-cf001 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.1-cf002 | |
IBM WebSphere Portal | =7.0.0.1-cf003 | |
IBM WebSphere Portal | =7.0.0.1-cf004 | |
IBM WebSphere Portal | =7.0.0.1-cf005 | |
IBM WebSphere Portal | =7.0.0.1-cf006 | |
IBM WebSphere Portal | =7.0.0.1-cf007 | |
IBM WebSphere Portal | =7.0.0.1-cf008 | |
IBM WebSphere Portal | =7.0.0.1-cf009 | |
IBM WebSphere Portal | =7.0.0.1-cf010 | |
IBM WebSphere Portal | =7.0.0.1-cf019 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =7.0.0.2-cf011 | |
IBM WebSphere Portal | =7.0.0.2-cf012 | |
IBM WebSphere Portal | =7.0.0.2-cf013 | |
IBM WebSphere Portal | =7.0.0.2-cf014 | |
IBM WebSphere Portal | =7.0.0.2-cf015 | |
IBM WebSphere Portal | =7.0.0.2-cf016 | |
IBM WebSphere Portal | =7.0.0.2-cf017 | |
IBM WebSphere Portal | =7.0.0.2-cf018 | |
IBM WebSphere Portal | =7.0.0.2-cf019 | |
IBM WebSphere Portal | =7.0.0.2-cf020 | |
IBM WebSphere Portal | =7.0.0.2-cf021 | |
IBM WebSphere Portal | =7.0.0.2-cf022 | |
IBM WebSphere Portal | =7.0.0.2-cf23 | |
IBM WebSphere Portal | =7.0.0.2-cf24 | |
IBM WebSphere Portal | =7.0.0.2-cf25 | |
IBM WebSphere Portal | =7.0.0.2-cf26 | |
IBM WebSphere Portal | =7.0.0.2-cf27 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.0-cf01 | |
IBM WebSphere Portal | =8.0.0.0-cf02 | |
IBM WebSphere Portal | =8.0.0.0-cf03 | |
IBM WebSphere Portal | =8.0.0.0-cf04 | |
IBM WebSphere Portal | =8.0.0.0-cf05 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.0.0.1-cf04 | |
IBM WebSphere Portal | =8.0.0.1-cf05 | |
IBM WebSphere Portal | =8.0.0.1-cf07 | |
IBM WebSphere Portal | =8.0.0.1-cf08 | |
IBM WebSphere Portal | =8.0.0.1-cf09 | |
IBM WebSphere Portal | =8.0.0.1-cf10 | |
IBM WebSphere Portal | =8.0.0.1-cf11 | |
IBM WebSphere Portal | =8.0.0.1-cf12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0958 is considered to have a high severity due to its potential for exploitation in open redirect attacks.
To fix CVE-2014-0958, update IBM WebSphere Portal to a version that includes the patch for this vulnerability.
CVE-2014-0958 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12.
CVE-2014-0958 allows attackers to perform phishing attacks by redirecting users to arbitrary web sites.
Yes, exploitation of CVE-2014-0958 typically requires user interaction to click on a malicious link.