← Back

Websphere Portal

websphere_portal

Vendor: Ibm • 126 CVEs

CVEs (126)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Ibm
Oracle
2Application Server
Websphere Portal
Apr 23, 2026
Apr 15, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
2Ibm
Oracle
2Application Server
Websphere Portal
Apr 23, 2026
Apr 15, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulner...Show more
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.Show less
1Ibm
1Websphere Portal
Apr 23, 2026
Dec 19, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuthTAI."
1Ibm
1Websphere Portal
Apr 23, 2026
Aug 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.
1Ibm
1Websphere Portal
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.
1Ibm
1Websphere Portal
Apr 23, 2026
Jun 19, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in...Show more
content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.Show less