Security vulnerability in Dojo for Portal versions 7.0.0.x and 8.0.

  • 16 May, 2013

Yesterday a costumer ask to update all servers because of this issue.

A URL manipulation security vulnerability has been found in the dojo module for WebSphere Portal versions 7.0.0.x and 8.0.

APAR PM64172 has been provided to address this issue.

The apar is included in CF14 for WebSphere Portal v7.0.0.1 and v7.0.0.2, and is available as an interim fix for WebSphere Portal v8.

This is a critical problem. When i simulate the attack i got the administrator password from security.xml

http://www-01.ibm.com/support/docview.wss?uid=swg21598363

Related Posts

Proud to be an HCL Ambassador 2021

  • 15 Dec, 2020

​If you have a problem, and no-one else can help, and if you can find them, maybe you can ask an HCL Ambassador… !(http://www.mysphere.com.br/wp-content/uploads/2020/12/HCLAmbassaborlight4x.png) See

Proud to be an HCL Ambassador 2021Read More

WebSphere Application Server Configuration Comparison Tool

  • 06 Sep, 2019

The Configuration Comparison Tool (CCT) is a lightweight wsadmin script and Python report generation script which will produce HTML reports on configuration settings for the following types of resourc

WebSphere Application Server Configuration Comparison ToolRead More

IBM Support Community for Digital Experience Products

  • 07 Nov, 2017

In the next week Digital Experience products: • WebSphere Portal • Web Content Manager • Digital Experience Patterns • Digital Experience on Cloud • Forms Experience Builder • Forms Experience Builde

IBM Support Community for Digital Experience ProductsRead More