CVE-2015-1946
IBM WebSphere Application Server 8.5 < 8.5.5.6 and WebSphere Virtual Enterprise 7.0 < 7.0.0.6 - Privilege Escalation
Title source: llmDescription
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.
References (3)
Core 3
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI35180
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21959083
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75496
Scores
EPSS
0.0035
EPSS Percentile
27.7%
Details
CWE
CWE-264
Status
published
Products (17)
ibm/websphere_application_server
7.0
ibm/websphere_application_server
8.0.0.0
ibm/websphere_application_server
8.5.0.0
ibm/websphere_application_server
8.5.0.1
ibm/websphere_application_server
8.5.0.2
ibm/websphere_application_server
8.5.5.0
ibm/websphere_application_server
8.5.5.1
ibm/websphere_application_server
8.5.5.2
ibm/websphere_application_server
8.5.5.3
ibm/websphere_application_server
8.5.5.4
... and 7 more
Published
Jul 14, 2015
Tracked Since
Feb 18, 2026