CVE-2014-3055: IBM WebSphere Portal
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
- IBM WebSphere Portal: version 7.0.0.0 only; version 7.0.0.1 only; version 7.0.0.2 only; version 8.0.0.0 only; version 8.0.0.1 only
- IBM WebSphere Portal Unified Task List Portlet: version 6.0.1 only
Published 2014-07-29. Last modified 2026-06-17.