First published: Sat Aug 22 2015(Updated: )
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Virtual Enterprise | <=7.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.8 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.9 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.10 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.11 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.12 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.13 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.14 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.15 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.16 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.17 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.18 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.19 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.21 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.22 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.23 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.24 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.25 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.27 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.29 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.31 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.32 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.33 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.34 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.36 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.37 | |
IBM WebSphere Application Server with Web Server Plug-ins | =7.0.0.38 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.6 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.7 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.8 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.9 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.0.0.10 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.0.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.1 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.2 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.3 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.4 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | =8.5.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1932 is rated as having moderate severity due to information disclosure risks.
To fix CVE-2015-1932, upgrade to IBM WebSphere Application Server version 7.0.0.39 or later, 8.0.0.11 or later, or 8.5.5.7 or later.
CVE-2015-1932 affects IBM WebSphere Application Server versions 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7.
Yes, CVE-2015-1932 can be exploited by remote attackers due to the information disclosure in the HTTP Via header.
CVE-2015-1932 may allow remote attackers to obtain sensitive information regarding the proxy-server software.