IBM WebSphere Portal open Redirection Vulnerability (CVE-2014-3054)
Release date:
Updated on:
Affected Systems:
IBM Websphere Portal 8.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3054
IBM WebSphere Portal is a framework that includes runtime servers, services, tools, and many other features-you can use these features to integrate an enterprise into a single customizable interface called a Portal.
WebSphere Portal 7.x, 8. the x-8.0.0.1 CF12 version of The uniied Task List (UTL) Portlet has multiple open redirection vulnerabilities on implementation that allow remote attackers to redirect users to arbitrary websites or perform phishing attacks.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: https://www-304.ibm.com/support/docview.wss? Uid = swg21677032
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://xforce.iss.net/xforce/xfdb/93529
Http://www.ibm.com/support/fixcentral/
This article permanently updates the link address: