First published: Tue Sep 15 2015(Updated: )
Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM HTTP Server | >=6.1.0.0<=6.1.0.47 | |
IBM HTTP Server | >=7.0.0.0<7.0.0.39 | |
IBM HTTP Server | >=8.0.0.0<8.0.0.12 | |
IBM HTTP Server | >=8.5.0.0<8.5.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4947 has been classified as a critical vulnerability due to the potential for remote code execution.
The recommended fix for CVE-2015-4947 is to apply the latest security patches provided by IBM for the affected versions of IBM HTTP Server.
CVE-2015-4947 affects users of IBM HTTP Server versions 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7.
CVE-2015-4947 allows remote authenticated users to execute arbitrary code, potentially leading to full system compromise.
Yes, CVE-2015-4947 is associated with the IBM HTTP Server and is used in various products including WebSphere Application Server.