CVE-2016-5954: Medium severity ibm websphere portal vulnerability
Published Sep 12, 2016
·Updated
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authenticated users to cause a denial of service by uploading temporary files.
Affected Software
17 affected components
IBM WebSphere Portal=6.1.0.0
IBM WebSphere Portal=6.1.0.1
IBM WebSphere Portal=6.1.0.2
IBM WebSphere Portal=6.1.0.3
IBM WebSphere Portal=6.1.0.4
IBM WebSphere Portal=6.1.0.5
IBM WebSphere Portal=6.1.0.6
IBM WebSphere Portal=6.1.5.0
IBM WebSphere Portal=6.1.5.1
IBM WebSphere Portal=6.1.5.2
IBM WebSphere Portal=6.1.5.3
IBM WebSphere Portal=7.0.0.0
IBM WebSphere Portal=7.0.0.1
IBM WebSphere Portal=7.0.0.2
IBM WebSphere Portal=8.0.0.0
IBM WebSphere Portal=8.0.0.1
IBM WebSphere Portal=8.5.0.0
Remediation
Patch Available
Event History
Sep 12, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5954?
CVE-2016-5954 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-5954?
To fix CVE-2016-5954, ensure that you apply the latest patches or updates provided by IBM for the WebSphere Portal.
3
Which versions of IBM WebSphere Portal are affected by CVE-2016-5954?
CVE-2016-5954 affects IBM WebSphere Portal versions 6.1.0 through 8.5.0 before CF12.
4
What kind of attack does CVE-2016-5954 enable?
CVE-2016-5954 allows remote authenticated users to upload temporary files, leading to potential denial of service.
5
Is CVE-2016-5954 a remote vulnerability?
Yes, CVE-2016-5954 allows authenticated remote users to exploit the vulnerability.