CVE-2015-1920
Last modified
CVE-2015-1920 is a vulnerability of currently unknown severity. IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.. EPSS estimates a 6.88% chance of exploitation in the next 30 days.
Description
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Application Server | 6.1 |
| Ibm | Websphere Application Server | 6.1.0 |
| Ibm | Websphere Application Server | 6.1.0.0 |
| Ibm | Websphere Application Server | 6.1.0.1 |
| Ibm | Websphere Application Server | 6.1.0.2 |
| Ibm | Websphere Application Server | 6.1.0.3 |
| Ibm | Websphere Application Server | 6.1.0.5 |
| Ibm | Websphere Application Server | 6.1.0.7 |
| Ibm | Websphere Application Server | 6.1.0.9 |
| Ibm | Websphere Application Server | 6.1.0.11 |
| Ibm | Websphere Application Server | 6.1.0.12 |
| Ibm | Websphere Application Server | 6.1.0.13 |
| Ibm | Websphere Application Server | 6.1.0.14 |
| Ibm | Websphere Application Server | 6.1.0.15 |
| Ibm | Websphere Application Server | 6.1.0.17 |
| Ibm | Websphere Application Server | 6.1.0.19 |
| Ibm | Websphere Application Server | 6.1.0.21 |
| Ibm | Websphere Application Server | 6.1.0.23 |
| Ibm | Websphere Application Server | 6.1.0.25 |
| Ibm | Websphere Application Server | 6.1.0.27 |
| Ibm | Websphere Application Server | 6.1.0.29 |
| Ibm | Websphere Application Server | 6.1.0.31 |
| Ibm | Websphere Application Server | 6.1.0.33 |
| Ibm | Websphere Application Server | 6.1.0.35 |
| Ibm | Websphere Application Server | 6.1.0.37 |
| Ibm | Websphere Application Server | 6.1.0.39 |
| Ibm | Websphere Application Server | 6.1.0.41 |
| Ibm | Websphere Application Server | 6.1.0.43 |
| Ibm | Websphere Application Server | 6.1.0.45 |
| Ibm | Websphere Application Server | 6.1.0.47 |
| Ibm | Websphere Application Server | 7.0 |
| Ibm | Websphere Application Server | 7.0.0.1 |
| Ibm | Websphere Application Server | 7.0.0.2 |
| Ibm | Websphere Application Server | 7.0.0.3 |
| Ibm | Websphere Application Server | 7.0.0.10 |
| Ibm | Websphere Application Server | 7.0.0.11 |
| Ibm | Websphere Application Server | 7.0.0.12 |
| Ibm | Websphere Application Server | 7.0.0.13 |
| Ibm | Websphere Application Server | 7.0.0.14 |
| Ibm | Websphere Application Server | 7.0.0.15 |
| Ibm | Websphere Application Server | 7.0.0.16 |
| Ibm | Websphere Application Server | 7.0.0.17 |
| Ibm | Websphere Application Server | 7.0.0.18 |
| Ibm | Websphere Application Server | 7.0.0.19 |
| Ibm | Websphere Application Server | 7.0.0.21 |
| Ibm | Websphere Application Server | 7.0.0.22 |
| Ibm | Websphere Application Server | 7.0.0.23 |
| Ibm | Websphere Application Server | 7.0.0.24 |
| Ibm | Websphere Application Server | 7.0.0.25 |
| Ibm | Websphere Application Server | 7.0.0.27 |
Showing 50 of 78 affected configurations. See NVD for the full list.
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21883573Patch, Vendor Advisory
- http://www.securityfocus.com/bid/74439Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032249Third Party Advisory, VDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg21883573Patch, Vendor Advisory
- http://www.securityfocus.com/bid/74439Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032249Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1920?
How severe is CVE-2015-1920?
How do I fix CVE-2015-1920?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1913Rational Test Control Panel in IBM Rational Test Workbench a…
- CVE-2015-1914IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4,…
- CVE-2015-1915The Endpoint Manager for Remote Control component in IBM Tiv…
- CVE-2015-1916Unspecified vulnerability in IBM Java 8 before SR1 allows re…7.5
- CVE-2015-1917Cross-site scripting (XSS) vulnerability in the Active Conte…
- CVE-2015-1919Cross-site scripting (XSS) vulnerability in IBM Security QRa…
- CVE-2015-1921Open redirect vulnerability in IBM WebSphere Portal 8.0.0 be…
- CVE-2015-1922The Data Movement implementation in IBM DB2 9.7 through FP10…
- CVE-2015-1923Buffer overflow in the server in IBM Tivoli Storage Manager …
- CVE-2015-1924Stack-based buffer overflow in the server in IBM Tivoli Stor…
- CVE-2015-1925Stack-based buffer overflow in the server in IBM Tivoli Stor…
- CVE-2015-1926Unspecified vulnerability in the Oracle WebCenter Portal com…
Are you affected by CVE-2015-1920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
