← Back

CVE-2014-4821

nvd nist
Published: Oct 28, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.

Affected (17)

1 product
Websphere Portal
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 6.1.0.0
Version 6.1.0.1
Version 6.1.0.2
Version 6.1.0.3
Version 6.1.0.4
Version 6.1.0.5
Version 6.1.0.6
Version 6.1.5.0
Version 6.1.5.1
Version 6.1.5.2
Version 6.1.5.3
Version 7.0.0.0
Version 7.0.0.1
Version 7.0.0.2
Version 8.0.0.0
Version 8.0.0.1
Version 8.5.0.0

References (8)

Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.