CVE-2015-1936: Medium severity ibm websphere application server feature pack for web services vulnerability
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1936?
CVE-2015-1936 is considered a high severity vulnerability due to its potential to allow session hijacking.
How do I fix CVE-2015-1936?
To fix CVE-2015-1936, upgrade IBM WebSphere Application Server to versions 8.0.0.11 and 8.5.5.6 or later.
Who is affected by CVE-2015-1936?
CVE-2015-1936 affects IBM WebSphere Application Server versions 8.0.0.0 through 8.0.0.10 and versions 8.5.0.0 through 8.5.5.5.
What is the attack vector for CVE-2015-1936?
The attack vector for CVE-2015-1936 allows remote authenticated users to hijack sessions via manipulation of the JSESSIONID parameter.
Is there a workaround for CVE-2015-1936?
Disabling the Security feature may mitigate CVE-2015-1936, but upgrading to a patched version is strongly recommended.