Lucene search

K
cve[email protected]CVE-2015-1946
HistoryJul 14, 2015 - 5:59 p.m.

CVE-2015-1946

2015-07-1417:59:02
CWE-264
web.nvd.nist.gov
45
ibm
websphere
application server
cve-2015-1946
local user
privilege escalation

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.

Affected configurations

NVD
Node
ibmwebsphere_application_serverMatch7.0
OR
ibmwebsphere_application_serverMatch8.0.0.0
OR
ibmwebsphere_application_serverMatch8.5.0.0
OR
ibmwebsphere_application_serverMatch8.5.0.1
OR
ibmwebsphere_application_serverMatch8.5.0.2
OR
ibmwebsphere_application_serverMatch8.5.5.0
OR
ibmwebsphere_application_serverMatch8.5.5.1
OR
ibmwebsphere_application_serverMatch8.5.5.2
OR
ibmwebsphere_application_serverMatch8.5.5.3
OR
ibmwebsphere_application_serverMatch8.5.5.4
OR
ibmwebsphere_application_serverMatch8.5.5.5
Node
ibmwebsphere_virtual_enterpriseMatch7.0
OR
ibmwebsphere_virtual_enterpriseMatch7.0.0.1
OR
ibmwebsphere_virtual_enterpriseMatch7.0.0.2
OR
ibmwebsphere_virtual_enterpriseMatch7.0.0.3
OR
ibmwebsphere_virtual_enterpriseMatch7.0.0.4
OR
ibmwebsphere_virtual_enterpriseMatch7.0.0.5

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%