Lucene search

K
cve[email protected]CVE-2015-1882
HistoryApr 27, 2015 - 12:59 p.m.

CVE-2015-1882

2015-04-2712:59:02
CWE-362
web.nvd.nist.gov
34
ibm
websphere
application server
cve-2015-1882
nvd
security issue
race conditions
java code execution
ejb run-as user

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

9.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.2%

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.

Affected configurations

NVD
Node
ibmwebsphere_application_serverMatch8.5.0.0
OR
ibmwebsphere_application_serverMatch8.5.0.1
OR
ibmwebsphere_application_serverMatch8.5.0.2
OR
ibmwebsphere_application_serverMatch8.5.5.0
OR
ibmwebsphere_application_serverMatch8.5.5.1
OR
ibmwebsphere_application_serverMatch8.5.5.2
OR
ibmwebsphere_application_serverMatch8.5.5.3
OR
ibmwebsphere_application_serverMatch8.5.5.4

8.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

9.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.2%

Related for CVE-2015-1882