CVE-2014-0959: Input Validation
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0959?
CVE-2014-0959 has a medium severity rating as it allows remote authenticated users to trigger a denial of service situation.
How do I fix CVE-2014-0959?
To fix CVE-2014-0959, upgrade your IBM WebSphere Portal to version 6.1.0.7 or later, 6.1.5.4 or later, 7.0.0.3 or later, or 8.0.0.1 or later.
What impact does CVE-2014-0959 have on IBM WebSphere Portal?
CVE-2014-0959 allows remote authenticated users to cause an infinite loop, leading to a denial of service.
Which IBM WebSphere Portal versions are affected by CVE-2014-0959?
CVE-2014-0959 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12.
Is CVE-2014-0959 relevant for un-authenticated users?
CVE-2014-0959 specifically affects remote authenticated users, so it is not a concern for unauthenticated users.