CVE Vulnerabilities

CVE-2015-4963

Published: Nov 08, 2015 | Modified: Dec 07, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Security_access_manager_for_web Ibm 7.0 (including) 7.0 (including)
Security_access_manager_for_web Ibm 7.0.0.1 (including) 7.0.0.1 (including)
Security_access_manager_for_web Ibm 7.0.0.2 (including) 7.0.0.2 (including)
Security_access_manager_for_web Ibm 7.0.0.3 (including) 7.0.0.3 (including)
Security_access_manager_for_web Ibm 7.0.0.4 (including) 7.0.0.4 (including)
Security_access_manager_for_web Ibm 7.0.0.5 (including) 7.0.0.5 (including)
Security_access_manager_for_web Ibm 7.0.0.6 (including) 7.0.0.6 (including)
Security_access_manager_for_web Ibm 7.0.0.7 (including) 7.0.0.7 (including)
Security_access_manager_for_web Ibm 7.0.0.8 (including) 7.0.0.8 (including)
Security_access_manager_for_web Ibm 7.0.0.9 (including) 7.0.0.9 (including)
Security_access_manager_for_web Ibm 7.0.0.10 (including) 7.0.0.10 (including)
Security_access_manager_for_web Ibm 7.0.0.11 (including) 7.0.0.11 (including)
Security_access_manager_for_web Ibm 7.0.0.12 (including) 7.0.0.12 (including)
Security_access_manager_for_web Ibm 7.0.0.13 (including) 7.0.0.13 (including)
Security_access_manager_for_web Ibm 7.0.0.14 (including) 7.0.0.14 (including)
Security_access_manager_for_web Ibm 7.0.0.15 (including) 7.0.0.15 (including)
Security_access_manager_for_web Ibm 8.0 (including) 8.0 (including)
Security_access_manager_for_web Ibm 8.0.0.2 (including) 8.0.0.2 (including)
Security_access_manager_for_web Ibm 8.0.0.3 (including) 8.0.0.3 (including)
Security_access_manager_for_web Ibm 8.0.0.4 (including) 8.0.0.4 (including)
Security_access_manager_for_web Ibm 8.0.0.5 (including) 8.0.0.5 (including)
Security_access_manager_for_web Ibm 8.0.0.22 (including) 8.0.0.22 (including)
Security_access_manager_for_web Ibm 8.0.0.31 (including) 8.0.0.31 (including)
Security_access_manager_for_web Ibm 8.0.1.0 (including) 8.0.1.0 (including)
Security_access_manager_for_web Ibm 8.0.1.1 (including) 8.0.1.1 (including)
Security_access_manager_for_web Ibm 8.0.1.2 (including) 8.0.1.2 (including)

References