CVE Vulnerabilities

CVE-2015-4963

Published: Nov 08, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Security_access_manager_for_webIbm7.0 (including)7.0 (including)
Security_access_manager_for_webIbm7.0.0.1 (including)7.0.0.1 (including)
Security_access_manager_for_webIbm7.0.0.2 (including)7.0.0.2 (including)
Security_access_manager_for_webIbm7.0.0.3 (including)7.0.0.3 (including)
Security_access_manager_for_webIbm7.0.0.4 (including)7.0.0.4 (including)
Security_access_manager_for_webIbm7.0.0.5 (including)7.0.0.5 (including)
Security_access_manager_for_webIbm7.0.0.6 (including)7.0.0.6 (including)
Security_access_manager_for_webIbm7.0.0.7 (including)7.0.0.7 (including)
Security_access_manager_for_webIbm7.0.0.8 (including)7.0.0.8 (including)
Security_access_manager_for_webIbm7.0.0.9 (including)7.0.0.9 (including)
Security_access_manager_for_webIbm7.0.0.10 (including)7.0.0.10 (including)
Security_access_manager_for_webIbm7.0.0.11 (including)7.0.0.11 (including)
Security_access_manager_for_webIbm7.0.0.12 (including)7.0.0.12 (including)
Security_access_manager_for_webIbm7.0.0.13 (including)7.0.0.13 (including)
Security_access_manager_for_webIbm7.0.0.14 (including)7.0.0.14 (including)
Security_access_manager_for_webIbm7.0.0.15 (including)7.0.0.15 (including)
Security_access_manager_for_webIbm8.0 (including)8.0 (including)
Security_access_manager_for_webIbm8.0.0.2 (including)8.0.0.2 (including)
Security_access_manager_for_webIbm8.0.0.3 (including)8.0.0.3 (including)
Security_access_manager_for_webIbm8.0.0.4 (including)8.0.0.4 (including)
Security_access_manager_for_webIbm8.0.0.5 (including)8.0.0.5 (including)
Security_access_manager_for_webIbm8.0.0.22 (including)8.0.0.22 (including)
Security_access_manager_for_webIbm8.0.0.31 (including)8.0.0.31 (including)
Security_access_manager_for_webIbm8.0.1.0 (including)8.0.1.0 (including)
Security_access_manager_for_webIbm8.0.1.1 (including)8.0.1.1 (including)
Security_access_manager_for_webIbm8.0.1.2 (including)8.0.1.2 (including)

References