Lucene search

K
cveIbmCVE-2015-2027
HistoryOct 04, 2015 - 2:59 a.m.

CVE-2015-2027

2015-10-0402:59:10
CWE-264
ibm
web.nvd.nist.gov
25
ibm
websphere
extreme scale
logout
bypass
vulnerability
cve-2015-2027
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

49.3%

IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

Affected configurations

Nvd
Node
ibmwebsphere_extreme_scaleMatch7.1.0
OR
ibmwebsphere_extreme_scaleMatch7.1.0.2
OR
ibmwebsphere_extreme_scaleMatch7.1.1
VendorProductVersionCPE
ibmwebsphere_extreme_scale7.1.0cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0:*:*:*:*:*:*:*
ibmwebsphere_extreme_scale7.1.0.2cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0.2:*:*:*:*:*:*:*
ibmwebsphere_extreme_scale7.1.1cpe:2.3:a:ibm:websphere_extreme_scale:7.1.1:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

49.3%

Related for CVE-2015-2027