First published: Tue Jul 14 2015(Updated: )
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.10 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1936 is considered a high severity vulnerability due to its potential to allow session hijacking.
To fix CVE-2015-1936, upgrade IBM WebSphere Application Server to versions 8.0.0.11 and 8.5.5.6 or later.
CVE-2015-1936 affects IBM WebSphere Application Server versions 8.0.0.0 through 8.0.0.10 and versions 8.5.0.0 through 8.5.5.5.
The attack vector for CVE-2015-1936 allows remote authenticated users to hijack sessions via manipulation of the JSESSIONID parameter.
Disabling the Security feature may mitigate CVE-2015-1936, but upgrading to a patched version is strongly recommended.