8.5
CVSSv2

CVE-2015-1882

Published: 27/04/2015 Updated: 04/08/2016
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile prior to 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 8.5.5.0

ibm websphere application server 8.5.5.1

ibm websphere application server 8.5.5.2

ibm websphere application server 8.5.5.3

ibm websphere application server 8.5.0.0

ibm websphere application server 8.5.0.2

ibm websphere application server 8.5.5.4

ibm websphere application server 8.5.0.1