First published: Fri Oct 10 2014(Updated: )
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =6.1.0.0 | |
IBM WebSphere Portal | =6.1.0.1 | |
IBM WebSphere Portal | =6.1.0.2 | |
IBM WebSphere Portal | =6.1.0.3 | |
IBM WebSphere Portal | =6.1.0.4 | |
IBM WebSphere Portal | =6.1.0.5 | |
IBM WebSphere Portal | =6.1.0.6 | |
IBM WebSphere Portal | =6.1.0.6-cf17 | |
IBM WebSphere Portal | =6.1.0.6-cf18 | |
IBM WebSphere Portal | =6.1.0.6-cf19 | |
IBM WebSphere Portal | =6.1.0.6-cf20 | |
IBM WebSphere Portal | =6.1.0.6-cf21 | |
IBM WebSphere Portal | =6.1.0.6-cf22 | |
IBM WebSphere Portal | =6.1.0.6-cf23 | |
IBM WebSphere Portal | =6.1.0.6-cf24 | |
IBM WebSphere Portal | =6.1.0.6-cf25 | |
IBM WebSphere Portal | =6.1.0.6-cf26 | |
IBM WebSphere Portal | =6.1.0.6-cf27 | |
IBM WebSphere Portal | =6.1.5.0 | |
IBM WebSphere Portal | =6.1.5.1 | |
IBM WebSphere Portal | =6.1.5.2 | |
IBM WebSphere Portal | =6.1.5.3 | |
IBM WebSphere Portal | =6.1.5.3-cf17 | |
IBM WebSphere Portal | =6.1.5.3-cf18 | |
IBM WebSphere Portal | =6.1.5.3-cf19 | |
IBM WebSphere Portal | =6.1.5.3-cf20 | |
IBM WebSphere Portal | =6.1.5.3-cf21 | |
IBM WebSphere Portal | =6.1.5.3-cf22 | |
IBM WebSphere Portal | =6.1.5.3-cf23 | |
IBM WebSphere Portal | =6.1.5.3-cf24 | |
IBM WebSphere Portal | =6.1.5.3-cf25 | |
IBM WebSphere Portal | =6.1.5.3-cf26 | |
IBM WebSphere Portal | =6.1.5.3-cf27 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.0-cf001 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.1-cf002 | |
IBM WebSphere Portal | =7.0.0.1-cf003 | |
IBM WebSphere Portal | =7.0.0.1-cf004 | |
IBM WebSphere Portal | =7.0.0.1-cf005 | |
IBM WebSphere Portal | =7.0.0.1-cf006 | |
IBM WebSphere Portal | =7.0.0.1-cf007 | |
IBM WebSphere Portal | =7.0.0.1-cf008 | |
IBM WebSphere Portal | =7.0.0.1-cf009 | |
IBM WebSphere Portal | =7.0.0.1-cf010 | |
IBM WebSphere Portal | =7.0.0.1-cf019 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =7.0.0.2-cf011 | |
IBM WebSphere Portal | =7.0.0.2-cf012 | |
IBM WebSphere Portal | =7.0.0.2-cf013 | |
IBM WebSphere Portal | =7.0.0.2-cf014 | |
IBM WebSphere Portal | =7.0.0.2-cf015 | |
IBM WebSphere Portal | =7.0.0.2-cf016 | |
IBM WebSphere Portal | =7.0.0.2-cf017 | |
IBM WebSphere Portal | =7.0.0.2-cf018 | |
IBM WebSphere Portal | =7.0.0.2-cf019 | |
IBM WebSphere Portal | =7.0.0.2-cf020 | |
IBM WebSphere Portal | =7.0.0.2-cf021 | |
IBM WebSphere Portal | =7.0.0.2-cf022 | |
IBM WebSphere Portal | =7.0.0.2-cf23 | |
IBM WebSphere Portal | =7.0.0.2-cf24 | |
IBM WebSphere Portal | =7.0.0.2-cf25 | |
IBM WebSphere Portal | =7.0.0.2-cf26 | |
IBM WebSphere Portal | =7.0.0.2-cf27 | |
IBM WebSphere Portal | =7.0.0.2-cf28 | |
IBM WebSphere Portal | =8.0 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.0-cf01 | |
IBM WebSphere Portal | =8.0.0.0-cf02 | |
IBM WebSphere Portal | =8.0.0.0-cf03 | |
IBM WebSphere Portal | =8.0.0.0-cf04 | |
IBM WebSphere Portal | =8.0.0.0-cf05 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.0.0.1-cf04 | |
IBM WebSphere Portal | =8.0.0.1-cf05 | |
IBM WebSphere Portal | =8.0.0.1-cf06 | |
IBM WebSphere Portal | =8.0.0.1-cf07 | |
IBM WebSphere Portal | =8.0.0.1-cf08 | |
IBM WebSphere Portal | =8.0.0.1-cf09 | |
IBM WebSphere Portal | =8.0.0.1-cf12 | |
IBM WebSphere Portal | =8.0.0.1-cf13 | |
IBM WebSphere Portal | =8.5.0.0 | |
IBM WebSphere Portal | =8.5.0.0-cf01 | |
IBM WebSphere Portal | =8.5.0.0-cf02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4761 has a medium severity due to its potential for information disclosure.
To fix CVE-2014-4761, update to the latest version of IBM WebSphere Portal that addresses this vulnerability.
CVE-2014-4761 affects IBM WebSphere Portal versions 6.1.0 through 8.5.0.0.
CVE-2014-4761 allows remote authenticated users to view sensitive credentials by reading HTML source code.
Currently, there are no known workarounds for CVE-2014-4761, making an update the recommended action.