CVE-2015-1893

IBM WebSphere DataPower XC10 Appliance Firmware < 2.1.0.3 - Session Hijacking

Title source: llm
STIX 2.1

Description

The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032025
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21701337
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73916
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT07841

Scores

EPSS 0.0169
EPSS Percentile 74.6%

Details

CWE
CWE-264
Status published
Products (3)
ibm/websphere_datapower_xc10_appliance_firmware 2.1.0.0
ibm/websphere_datapower_xc10_appliance_firmware 2.1.0.1
ibm/websphere_datapower_xc10_appliance_firmware 2.1.0.2
Published Apr 06, 2015
Tracked Since Feb 18, 2026