Lucene search

K
cveIbmCVE-2015-4947
HistorySep 15, 2015 - 3:59 p.m.

CVE-2015-4947

2015-09-1515:59:00
CWE-119
ibm
web.nvd.nist.gov
81
cve
2015
4947
buffer overflow
ibm http server
websphere application server
nvd
security vulnerability
code execution

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

9.3

Confidence

High

EPSS

0.004

Percentile

72.3%

Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.

Affected configurations

Nvd
Node
ibmhttp_serverRange6.1.0.06.1.0.47
OR
ibmhttp_serverRange7.0.0.07.0.0.39
OR
ibmhttp_serverRange8.0.0.08.0.0.12
OR
ibmhttp_serverRange8.5.0.08.5.5.7
VendorProductVersionCPE
ibmhttp_server*cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

9.3

Confidence

High

EPSS

0.004

Percentile

72.3%

Related for CVE-2015-4947