SQL Injection Vulnerability in IBM WebSphere Portal 7.x and 8.x
CVE-2014-3055

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 July 2014

Summary

An SQL injection vulnerability exists in the Unified Task List (UTL) portlet of IBM WebSphere Portal, affecting versions 7.x and 8.x through 8.0.0.1 CF12. This flaw allows remote attackers to execute arbitrary SQL commands through unspecified vectors, potentially compromising the integrity and confidentiality of the application's database. Organizations using affected versions should apply necessary patches and follow best security practices to mitigate the risk of exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.