CVE-2014-3416
Public on 2014-05-29
Modified on 2015-07-07
Description
uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | php54 | 2015-07-07 | ALAS-2015-561 | Fixed |
Amazon Linux 1 | php55 | 2015-07-07 | ALAS-2015-562 | Fixed |
Amazon Linux 1 | php56 | 2015-07-07 | ALAS-2015-563 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
NVD | CVSSv2 | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P |