6.8
CVSSv2

CVE-2015-1927

Published: 14/07/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 prior to 7.0.0.39, 8.0.0 prior to 8.0.0.11, and 8.5 prior to 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote malicious users to obtain privileged access via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere application server 7.0.0.13

ibm websphere application server 7.0.0.11

ibm websphere application server 7.0.0.12

ibm websphere application server 7.0.0.19

ibm websphere application server 7.0.0.2

ibm websphere application server 7.0.0.29

ibm websphere application server 7.0.0.3

ibm websphere application server 7.0.0.4

ibm websphere application server 7.0.0.5

ibm websphere application server 8.0.0.10

ibm websphere application server 8.0.0.2

ibm websphere application server 8.0.0.9

ibm websphere application server 8.5.0.0

ibm websphere application server 8.5.5.5

ibm websphere application server 7.0

ibm websphere application server 7.0.0.1

ibm websphere application server 7.0.0.10

ibm websphere application server 7.0.0.17

ibm websphere application server 7.0.0.18

ibm websphere application server 7.0.0.25

ibm websphere application server 7.0.0.27

ibm websphere application server 7.0.0.37

ibm websphere application server 7.0.0.38

ibm websphere application server 8.0.0.0

ibm websphere application server 8.0.0.1

ibm websphere application server 8.0.0.7

ibm websphere application server 8.0.0.8

ibm websphere application server 8.5.5.3

ibm websphere application server 8.5.5.4

ibm websphere application server 7.0.0.14

ibm websphere application server 7.0.0.21

ibm websphere application server 7.0.0.22

ibm websphere application server 7.0.0.31

ibm websphere application server 7.0.0.32

ibm websphere application server 7.0.0.6

ibm websphere application server 7.0.0.7

ibm websphere application server 8.0.0.3

ibm websphere application server 8.0.0.4

ibm websphere application server 8.5.0.1

ibm websphere application server 8.5.0.2

ibm websphere application server 7.0.0.15

ibm websphere application server 7.0.0.16

ibm websphere application server 7.0.0.23

ibm websphere application server 7.0.0.24

ibm websphere application server 7.0.0.33

ibm websphere application server 7.0.0.34

ibm websphere application server 7.0.0.36

ibm websphere application server 7.0.0.8

ibm websphere application server 7.0.0.9

ibm websphere application server 8.0.0.5

ibm websphere application server 8.0.0.6

ibm websphere application server 8.5.5.0

ibm websphere application server 8.5.5.1

ibm websphere application server 8.5.5.2