CVE Vulnerabilities

CVE-2015-1893

Published: Apr 06, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Websphere_datapower_xc10_appliance_firmwareIbm2.1.0.0 (including)2.1.0.0 (including)
Websphere_datapower_xc10_appliance_firmwareIbm2.1.0.1 (including)2.1.0.1 (including)
Websphere_datapower_xc10_appliance_firmwareIbm2.1.0.2 (including)2.1.0.2 (including)

References