First published: Mon Feb 29 2016(Updated: )
IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7455 has a medium severity rating due to weak permissions allowing unauthorized modifications.
To fix CVE-2015-7455, update IBM WebSphere Portal to the latest version that addresses this vulnerability.
CVE-2015-7455 affects IBM WebSphere Portal versions 7.0.0.0 through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09.
CVE-2015-7455 can be exploited by remote authenticated users to unauthorizedly modify content items through the authoring UI.
While the best solution is to update, temporarily restricting access to the authoring UI can serve as a workaround for CVE-2015-7455.