CVE-2015-7447

medium

Description

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF09 allows remote attackers to bypass intended Portal AccessControl REST API access restrictions and obtain sensitive information via unspecified vectors.

References

http://www.securitytracker.com/id/1034538

http://www.securityfocus.com/bid/79511

http://www-01.ibm.com/support/docview.wss?uid=swg21973152

http://www-01.ibm.com/support/docview.wss?uid=swg1PI51395

Details

Source: Mitre, NVD

Published: 2015-12-31

Updated: 2016-12-07

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium