Id:
CVE-2015-7472
Comment
:
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.
CVSSv2 Score:
6.4
Access vector:
|
NETWORK
|
Access complexity:
|
LOW
|
Authentication:
|
NONE
|
Confidentiality impact:
|
PARTIAL
|
Integrity impact:
|
PARTIAL
|
Availability impact:
|
NONE
|
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N
CVSSv3 Score:
7.2
Attack vector:
|
NETWORK
|
Attack complexity:
|
LOW
|
Privileges required:
|
NONE
|
User interaction:
|
NONE
|
Scope:
|
CHANGED
|
Confidentiality impact:
|
LOW
|
Integrity impact:
|
LOW
|
Availability impact:
|
NONE
|
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
References: