Denial of service in IBM WebSphere Commerce



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2016-5954
CWE-ID CWE-399
Exploitation vector Network
Public exploit N/A
Vulnerable software
WebSphere Portal
Server applications / Application servers

Vendor IBM Corporation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper input validation

EUVDB-ID: #VU404

Risk: Low

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2016-5954

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to cause denial of service.

The weakness exists in IBM WebSphere Portal  due to possibility to upload temporary files. A remote authenticated attacker can cause denial of service (DoS).

Successful exploitation of this vulnerability may result in denial of service.

Mitigation

The recommended solution is to apply Interim Fix PI67037 or a Cumulative Fix containing it as soon as practical.

For 8.5.0


For 8.0.0 through 8.0.0.1
For 7.0.0 through 7.0.0.2
For 6.1.5.0 through 6.1.5.3
For 6.1.0.0 through 6.1.0.6

Vulnerable software versions

WebSphere Portal: 6.1.0.0 - 8.5.0.0

CPE2.3 External links

https://www-01.ibm.com/support/docview.wss?uid=swg21989993


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###