CVE-2014-0958: Medium severity IBM WebSphere Portal vulnerability
Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0958?
CVE-2014-0958 is considered to have a high severity due to its potential for exploitation in open redirect attacks.
How do I fix CVE-2014-0958?
To fix CVE-2014-0958, update IBM WebSphere Portal to a version that includes the patch for this vulnerability.
What versions of IBM WebSphere Portal are affected by CVE-2014-0958?
CVE-2014-0958 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12.
What type of attack is enabled by CVE-2014-0958?
CVE-2014-0958 allows attackers to perform phishing attacks by redirecting users to arbitrary web sites.
Is user intervention required to exploit CVE-2014-0958?
Yes, exploitation of CVE-2014-0958 typically requires user interaction to click on a malicious link.