CVE-2015-1885
IBM WebSphere Application Server 7.0-8.5 - Privilege Escalation via OAuth Password Grant Type
Title source: llmDescription
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032190
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21697368
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/74219
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21963275
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI33202
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI36211
Scores
EPSS
0.0344
EPSS Percentile
87.7%
Details
CWE
CWE-264
Status
published
Products (37)
ibm/websphere_application_server
7.0
ibm/websphere_application_server
7.0.0.1
ibm/websphere_application_server
7.0.0.2
ibm/websphere_application_server
7.0.0.3
ibm/websphere_application_server
7.0.0.10
ibm/websphere_application_server
7.0.0.11
ibm/websphere_application_server
7.0.0.12
ibm/websphere_application_server
7.0.0.13
ibm/websphere_application_server
7.0.0.14
ibm/websphere_application_server
7.0.0.15
... and 27 more
Published
Apr 27, 2015
Tracked Since
Feb 18, 2026