Vulnerability Name: | CVE-2015-2027 (CCN-104056) | ||||||||
Assigned: | 2015-09-08 | ||||||||
Published: | 2015-09-08 | ||||||||
Updated: | 2015-10-05 | ||||||||
Summary: | IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. Per http://www-01.ibm.com/support/docview.wss?uid=swg21966044: " IBM WebSphere Extreme Scale could allow a local user to bypass security on another user's session due to it improperly logging out the previous user." | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-2027 Source: AIXAPAR Type: Patch, Vendor Advisory PI44098 Source: AIXAPAR Type: Patch, Vendor Advisory PI44105 Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21966044 Source: CCN Type: IBM Security Bulletin 1966044 : The WebSphere eXtreme Scale 7.1.0 and 7.1.1 monitoring console lacks protection for various vulnerabilities. (CVE-2015-2025 CVE-2015-2026 CVE-2015-2027 CVE-2015-2028 CVE-2015-2029 CVE-2015-2030 CVE-2015-2031) Source: CCN Type: IBM Security Bulletin 1966045 The WebSphere eXtreme Scale 8.5 and 8.6 monitoring console lacks protection for various vulnerabilities. (CVE-2015-2025 CVE-2015-2026 CVE-2015-2027 CVE-2015-2029 CVE-2015-2030) Source: XF Type: UNKNOWN ibm-websphere-cve20152027-sec-bypass(104056) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |