IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.
http://www.ibm.com/support/docview.wss?uid=swg21975358
http://www-01.ibm.com/support/docview.wss?uid=swg1PI51234
Source: Mitre, NVD
Published: 2016-02-29
Updated: 2024-11-21
Base Score: 4
Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N
Severity: Medium
Base Score: 3.1
Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity: Low