The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-07-14 10:59
Updated : 2016-12-21 18:59
NVD link : CVE-2015-1927
Mitre link : CVE-2015-1927
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
ibm
- websphere_application_server