CVE-2014-8912
Summary
| CVE | CVE-2014-8912 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-28 18:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by configuration information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Portal | 6.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.0.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.5 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.6 | All | All | All |
| Application | Ibm | Websphere Portal | 6.0.1.7 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.3 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.4 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.5 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.0.6 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.0 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.1 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.2 | All | All | All |
| Application | Ibm | Websphere Portal | 6.1.5.3 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Portal | 8.0.0.1 | All | All | All |
| Application | Ibm | Websphere Portal | 8.5.0.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM WebSphere Portal Bug Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM Security Bulletin: Fix Available for Security Vulnerability in IBM WebSphere Portal (CVE-2014-8912) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.