CVE-2015-1946
Summary
| CVE | CVE-2015-1946 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-14 17:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Application Server | 7.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.5.5 | All | All | All |
| Application | Ibm | Websphere Virtual Enterprise | 7.0 | All | All | All |
| Application | Ibm | Websphere Virtual Enterprise | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Virtual Enterprise | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Virtual Enterprise | 7.0.0.3 | All | All | All |
| Application | Ibm | Websphere Virtual Enterprise | 7.0.0.4 | All | All | All |
| Application | Ibm | Websphere Virtual Enterprise | 7.0.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple IBM Products CVE-2015-1946 Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM Security Bulletin: Multiple Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.5.6 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.