CVE-2015-1885: Critical severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1885?
CVE-2015-1885 has been classified with a medium severity due to potential unauthorized access and privilege escalation risks.
How do I fix CVE-2015-1885?
To mitigate CVE-2015-1885, update IBM WebSphere Application Server to version 7.0.0.39 or later, 8.0.0.11 or later, 8.5 Liberty Profile to 8.5.5.5 or later, and Full Profile to 8.5.5.6 or later.
What are the affected IBM WebSphere Application Server versions for CVE-2015-1885?
CVE-2015-1885 affects WebSphere Application Server versions 7.0, 8.0, and 8.5 prior to certain patch levels.
Can CVE-2015-1885 be exploited remotely?
Yes, CVE-2015-1885 allows remote attackers to potentially exploit the vulnerability to gain unauthorized privileges.
Is there a patch available for CVE-2015-1885?
Yes, IBM has released patches to address CVE-2015-1885 as part of their software version updates.