CVE-2015-4963
Published Nov 8, 2015
Last updated 8 years ago
Overview
- Description
- IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-17
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4133E7B3-02B3-44C8-BBD7-234E06C3EC70" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0ACEB654-5337-4C34-907A-FD63DE420825" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BF73213F-5BBF-4C29-8E43-1D83347BA615" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "823EDC19-5D2B-4AE3-955B-E236EABA7619" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD31CD02-A79B-4BF3-8D61-56924282D413" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13157D89-B086-4FCA-B4A2-A75D7DB86225" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BC24772-EA02-4E4E-8CC9-2F8572090DC0" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "708CD9B7-0488-49D4-9CEE-06A4FC3BEF64" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6904A5F5-0844-49B3-A9DA-085CD9669891" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA0D73EA-17FF-4410-B8AF-F09913C7B873" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FB55332-6F59-4C14-B9AC-2A583047F11F" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F165D2F0-120B-459A-9C2B-11D6C67DDB60" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C156FBDE-501A-49DD-BF04-188261BAF201" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6945F705-54EC-4A12-A9A3-BF0B78E81F9A" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17D95C29-60E2-47E9-B7FD-20AA803E548D" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:7.0.0.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A1AA334-093F-41CC-94E5-B7C2E5396EEB" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A4AD958-FDB2-4F63-AD4F-C88B33BFA692" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F807870-4976-43E1-89BE-F08DEEE109CD" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2B3E49D-08E6-44CF-B034-D155247B5DB9" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9F50A5E-111B-4CF6-A531-FE88E7735140" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D54372BE-6201-48AB-A720-F29E931E52B3" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BCCE958E-6DFA-403E-B251-F5BA7825A546" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.0.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9DA2F71C-E15F-4729-A0D9-C8C116819546" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39017599-E63F-4101-8D37-62D9B0CE6917" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB037932-234B-41AD-8119-D964796ADDFD" }, { "criteria": "cpe:2.3:a:ibm:security_access_manager_for_web:8.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BA1DA71-91C8-4989-98B9-E924ED7B272A" } ], "operator": "OR" } ] } ]