CVE-2015-1893
IBM WebSphere DataPower XC10 Appliance Firmware < 2.1.0.3 - Session Hijacking
Title source: llmDescription
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032025
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21701337
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/73916
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT07841
Scores
EPSS
0.0169
EPSS Percentile
74.6%
Details
CWE
CWE-264
Status
published
Products (3)
ibm/websphere_datapower_xc10_appliance_firmware
2.1.0.0
ibm/websphere_datapower_xc10_appliance_firmware
2.1.0.1
ibm/websphere_datapower_xc10_appliance_firmware
2.1.0.2
Published
Apr 06, 2015
Tracked Since
Feb 18, 2026