CVE Vulnerabilities

CVE-2015-1946

Published: Jul 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Websphere_application_serverIbm7.0 (including)7.0 (including)
Websphere_application_serverIbm8.0.0.0 (including)8.0.0.0 (including)
Websphere_application_serverIbm8.5.0.0 (including)8.5.0.0 (including)
Websphere_application_serverIbm8.5.0.1 (including)8.5.0.1 (including)
Websphere_application_serverIbm8.5.0.2 (including)8.5.0.2 (including)
Websphere_application_serverIbm8.5.5.0 (including)8.5.5.0 (including)
Websphere_application_serverIbm8.5.5.1 (including)8.5.5.1 (including)
Websphere_application_serverIbm8.5.5.2 (including)8.5.5.2 (including)
Websphere_application_serverIbm8.5.5.3 (including)8.5.5.3 (including)
Websphere_application_serverIbm8.5.5.4 (including)8.5.5.4 (including)
Websphere_application_serverIbm8.5.5.5 (including)8.5.5.5 (including)

References