First published: Sat Nov 14 2015(Updated: )
IBM WebSphere Portal 8.0.0.1 before CF19 and 8.5.0 before CF09 allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.0.0.1-cf04 | |
IBM WebSphere Portal | =8.0.0.1-cf05 | |
IBM WebSphere Portal | =8.0.0.1-cf06 | |
IBM WebSphere Portal | =8.0.0.1-cf07 | |
IBM WebSphere Portal | =8.0.0.1-cf08 | |
IBM WebSphere Portal | =8.0.0.1-cf09 | |
IBM WebSphere Portal | =8.0.0.1-cf10 | |
IBM WebSphere Portal | =8.0.0.1-cf11 | |
IBM WebSphere Portal | =8.0.0.1-cf12 | |
IBM WebSphere Portal | =8.0.0.1-cf13 | |
IBM WebSphere Portal | =8.0.0.1-cf14 | |
IBM WebSphere Portal | =8.0.0.1-cf15 | |
IBM WebSphere Portal | =8.0.0.1-cf16 | |
IBM WebSphere Portal | =8.0.0.1-cf17 | |
IBM WebSphere Portal | =8.0.0.1-cf18 | |
IBM WebSphere Portal | =8.5.0.0 | |
IBM WebSphere Portal | =8.5.0.0-cf1 | |
IBM WebSphere Portal | =8.5.0.0-cf2 | |
IBM WebSphere Portal | =8.5.0.0-cf3 | |
IBM WebSphere Portal | =8.5.0.0-cf4 | |
IBM WebSphere Portal | =8.5.0.0-cf5 | |
IBM WebSphere Portal | =8.5.0.0-cf6 | |
IBM WebSphere Portal | =8.5.0.0-cf7 | |
IBM WebSphere Portal | =8.5.0.0-cf8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7419 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
To fix CVE-2015-7419, upgrade IBM WebSphere Portal to version 8.0.0.1 or 8.5.0 to the latest cumulative fix level.
CVE-2015-7419 affects IBM WebSphere Portal versions 8.0.0.1 before CF19 and 8.5.0 before CF09.
Yes, CVE-2015-7419 can be exploited remotely by attackers sending crafted requests.
The impact of CVE-2015-7419 is primarily denial of service, leading to elevated memory consumption that affects availability.