CVE-2015-5004: Infoleak
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2015-5004?
CVE-2015-5004 allows remote authenticated users to access sensitive data due to improper encryption in the Edge Component Caching Proxy of IBM WebSphere Application Server.
What versions of IBM WebSphere Application Server are affected by CVE-2015-5004?
CVE-2015-5004 affects IBM WebSphere Application Server versions 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8.
How can I mitigate the risks associated with CVE-2015-5004?
Mitigation for CVE-2015-5004 involves upgrading to IBM WebSphere Application Server versions 8.0.0.12 or 8.5.5.8 and above.
What type of vulnerability is CVE-2015-5004 classified as?
CVE-2015-5004 is classified as a security vulnerability related to insufficient encryption.
Is there a patch available for CVE-2015-5004?
Yes, IBM has released patches for CVE-2015-5004 in the updated versions of WebSphere Application Server.