CVE-2014-4821: Infoleak
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4821?
CVE-2014-4821 is considered a medium-severity vulnerability that enables remote attackers to gain insights about file existence on the server.
How do I fix CVE-2014-4821?
To fix CVE-2014-4821, you should update your IBM WebSphere Portal to the latest version or apply the recommended patches from IBM.
Which versions of IBM WebSphere Portal are affected by CVE-2014-4821?
CVE-2014-4821 affects IBM WebSphere Portal versions from 6.1.0 to 8.5.0 before certain fix packs.
What type of attack does CVE-2014-4821 allow?
CVE-2014-4821 allows remote attackers to determine the validity of files on the server through different web-server error codes.
Is authentication required to exploit CVE-2014-4821?
CVE-2014-4821 can be exploited without authentication, allowing unauthenticated users to check for file existence.