Vulnerability CVE-2015-1882


Published: 2015-04-27

Description:
Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.

CVSS2 => (AV:N/AC:M/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
8.5/10
10/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
IBM -> Websphere application server 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg1PI33357
http://www-01.ibm.com/support/docview.wss?uid=swg21697368
http://www.securityfocus.com/bid/74222
http://www.securitytracker.com/id/1032190

Copyright 2024, cxsecurity.com

 

Back to Top