CVE-2015-1887: Infoleak
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1887?
CVE-2015-1887 is classified as a medium severity vulnerability.
How do I fix CVE-2015-1887?
To fix CVE-2015-1887, upgrade to the patched versions of IBM WebSphere Portal 7.0.0.3, 8.0.0.1 CF18, or 8.5.0 CF07 or later.
What impact does CVE-2015-1887 have on users?
CVE-2015-1887 allows remote attackers to access sensitive information from the Java Content Repository (JCR) of the affected IBM WebSphere Portal versions.
Which versions of IBM WebSphere Portal are affected by CVE-2015-1887?
CVE-2015-1887 affects IBM WebSphere Portal versions 7.0.0 through 7.0.0.2, 8.0.0 before 8.0.0.1, and 8.5.0 before CF06.
Is there a workaround for CVE-2015-1887?
There are no known workarounds for CVE-2015-1887; upgrading to a secure version is the recommended action.