First published: Sun Nov 08 2015(Updated: )
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Web Appliance | =7.0 | |
IBM Security Access Manager for Web Appliance | =7.0.0.1 | |
IBM Security Access Manager for Web Appliance | =7.0.0.2 | |
IBM Security Access Manager for Web Appliance | =7.0.0.3 | |
IBM Security Access Manager for Web Appliance | =7.0.0.4 | |
IBM Security Access Manager for Web Appliance | =7.0.0.5 | |
IBM Security Access Manager for Web Appliance | =7.0.0.6 | |
IBM Security Access Manager for Web Appliance | =7.0.0.7 | |
IBM Security Access Manager for Web Appliance | =7.0.0.8 | |
IBM Security Access Manager for Web Appliance | =7.0.0.9 | |
IBM Security Access Manager for Web Appliance | =7.0.0.10 | |
IBM Security Access Manager for Web Appliance | =7.0.0.11 | |
IBM Security Access Manager for Web Appliance | =7.0.0.12 | |
IBM Security Access Manager for Web Appliance | =7.0.0.13 | |
IBM Security Access Manager for Web Appliance | =7.0.0.14 | |
IBM Security Access Manager for Web Appliance | =7.0.0.15 | |
IBM Security Access Manager for Web Appliance | =8.0 | |
IBM Security Access Manager for Web Appliance | =8.0.0.2 | |
IBM Security Access Manager for Web Appliance | =8.0.0.3 | |
IBM Security Access Manager for Web Appliance | =8.0.0.4 | |
IBM Security Access Manager for Web Appliance | =8.0.0.5 | |
IBM Security Access Manager for Web Appliance | =8.0.0.22 | |
IBM Security Access Manager for Web Appliance | =8.0.0.31 | |
IBM Security Access Manager for Web Appliance | =8.0.1.0 | |
IBM Security Access Manager for Web Appliance | =8.0.1.1 | |
IBM Security Access Manager for Web Appliance | =8.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4963 is classified as a critical vulnerability due to its potential for remote file access.
To fix CVE-2015-4963, users should apply the latest updates to IBM Security Access Manager for Web, specifically versions 7.0.0.16 or higher and 8.0.1.3 or higher.
CVE-2015-4963 allows remote attackers to read or write to arbitrary files on the server.
CVE-2015-4963 affects IBM Security Access Manager for Web versions 7.x before 7.0.0.16 and 8.x before 8.0.1.3.
CVE-2015-4963 can be exploited by remote attackers who can send crafted HTTPTransformation requests.