SQL Injection Vulnerability in IBM WebSphere Portal 7.x and 8.x
CVE-2014-3055
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 29 July 2014
Summary
An SQL injection vulnerability exists in the Unified Task List (UTL) portlet of IBM WebSphere Portal, affecting versions 7.x and 8.x through 8.0.0.1 CF12. This flaw allows remote attackers to execute arbitrary SQL commands through unspecified vectors, potentially compromising the integrity and confidentiality of the application's database. Organizations using affected versions should apply necessary patches and follow best security practices to mitigate the risk of exploitation.
References
Timeline
Vulnerability published
Vulnerability Reserved