CVE-2014-0954

medium
Published 2014-05-22 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21672572

Application impact

VendorProductVersionsFixed
ibm ibmwebsphere_portal6.1.0.0
ibm ibmwebsphere_portal6.1.0.1
ibm ibmwebsphere_portal6.1.0.2
ibm ibmwebsphere_portal6.1.0.3
ibm ibmwebsphere_portal6.1.0.4
ibm ibmwebsphere_portal6.1.0.5
ibm ibmwebsphere_portal6.1.0.6
ibm ibmwebsphere_portal6.1.5.0
ibm ibmwebsphere_portal6.1.5.1
ibm ibmwebsphere_portal6.1.5.2
ibm ibmwebsphere_portal6.1.5.3
ibm ibmwebsphere_portal7.0.0.0
ibm ibmwebsphere_portal7.0.0.1
ibm ibmwebsphere_portal7.0.0.2
ibm ibmwebsphere_portal8.0.0.0
ibm ibmwebsphere_portal8.0.0.1

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.