CVE

Id
68363  
CVE No.
CVE-2014-0954  
Status
Candidate  
Description
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.  
Phase
Assigned (20140106)  
Votes
None (candidate not yet proposed)  
Comments