CVE-2015-4963: High severity ibm security access manager for web appliance vulnerability
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4963?
CVE-2015-4963 is classified as a critical vulnerability due to its potential for remote file access.
How do I fix CVE-2015-4963?
To fix CVE-2015-4963, users should apply the latest updates to IBM Security Access Manager for Web, specifically versions 7.0.0.16 or higher and 8.0.1.3 or higher.
What types of files can be affected by CVE-2015-4963?
CVE-2015-4963 allows remote attackers to read or write to arbitrary files on the server.
What versions of IBM Security Access Manager for Web are affected by CVE-2015-4963?
CVE-2015-4963 affects IBM Security Access Manager for Web versions 7.x before 7.0.0.16 and 8.x before 8.0.1.3.
Who can exploit CVE-2015-4963?
CVE-2015-4963 can be exploited by remote attackers who can send crafted HTTPTransformation requests.