IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/101271 | vdb entry |
http://www.securityfocus.com/bid/64488 | third party advisory vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21660011 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89278 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI05684 | vendor advisory not applicable |