Vulnerability CVE-2015-1893


Published: 2015-04-05   Modified: 2015-04-06

Description:
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
IBM -> Websphere datapower xc10 appliance firmware 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg1IT07841
http://www-01.ibm.com/support/docview.wss?uid=swg21701337
http://www.securityfocus.com/bid/73916
http://www.securitytracker.com/id/1032025

Copyright 2024, cxsecurity.com

 

Back to Top