CVE-2014-3055: SQL Injection
SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3055?
CVE-2014-3055 has a high severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2014-3055?
To address CVE-2014-3055, upgrade IBM WebSphere Portal to a version that includes the necessary patches provided by IBM.
What versions of IBM WebSphere Portal are affected by CVE-2014-3055?
CVE-2014-3055 affects IBM WebSphere Portal versions 7.x and 8.x, particularly up to version 8.0.0.1 CF12.
Can CVE-2014-3055 be exploited without authentication?
Yes, CVE-2014-3055 can be exploited by remote attackers without requiring authentication, making it particularly dangerous.
What component is impacted by CVE-2014-3055?
CVE-2014-3055 impacts the Unified Task List (UTL) Portlet of IBM WebSphere Portal.