{"api_version":"1","generated_at":"2026-07-23T06:44:48+00:00","cve":"CVE-2015-1882","urls":{"html":"https://cve.report/CVE-2015-1882","api":"https://cve.report/api/cve/CVE-2015-1882.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1882","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1882"},"summary":{"title":"CVE-2015-1882","description":"Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.","state":"PUBLISHED","assigner":"ibm","published_at":"2015-04-27 12:59:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-362","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21697368","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21697368","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM Security Bulletin: Potential Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.5.5 - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI33357","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI33357","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.securityfocus.com/bid/74222","name":"http://www.securityfocus.com/bid/74222","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM WebSphere Application Server CVE-2015-1882 Remote Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1032190","name":"http://www.securitytracker.com/id/1032190","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM WebSphere Application Server Bugs Let Remote and Remote Authenticated Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1882","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1882","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1882","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_application_server","cpe6":"8.5.5.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:54:16.509Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"74222","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/74222"},{"name":"1032190","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1032190"},{"name":"PI33357","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI33357"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21697368"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-07-22T16:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"74222","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/74222"},{"name":"1032190","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1032190"},{"name":"PI33357","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI33357"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21697368"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2015-1882","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"74222","refsource":"BID","url":"http://www.securityfocus.com/bid/74222"},{"name":"1032190","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032190"},{"name":"PI33357","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI33357"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21697368","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21697368"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2015-1882","datePublished":"2015-04-26T10:00:00.000Z","dateReserved":"2015-02-19T00:00:00.000Z","dateUpdated":"2024-08-06T04:54:16.509Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-04-27 12:59:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-362","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"1FD8F9CE-4E98-4187-B84A-429FA1C65E2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"FC1D7570-4AB4-44B0-B5ED-D103F0946F63"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.0.2:*:*:*:*:*:*:*","matchCriteriaId":"9E709E36-B5D0-42E5-A305-AF385FD7F347"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.5.0:*:*:*:*:*:*:*","matchCriteriaId":"49506702-1B31-4421-8DEE-5B789272EC6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.5.1:*:*:*:*:*:*:*","matchCriteriaId":"158777FD-83D1-44B9-83B4-A3F490CA76F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.5.2:*:*:*:*:*:*:*","matchCriteriaId":"EDA2FE6B-6E42-4E97-B803-DAB671D30FF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.5.3:*:*:*:*:*:*:*","matchCriteriaId":"72F5A562-5B2E-4BC7-8A81-EFE5ED265803"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_application_server:8.5.5.4:*:*:*:*:*:*:*","matchCriteriaId":"168E2F18-56C6-4789-BBAC-C99D4792046F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1882","Ordinal":"1","Title":"CVE-2015-1882","CVE":"CVE-2015-1882","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1882","Ordinal":"1","NoteData":"Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.","Type":"Description","Title":"CVE-2015-1882"},{"CveYear":"2015","CveId":"1882","Ordinal":"2","NoteData":"2015-04-26","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1882","Ordinal":"3","NoteData":"2016-07-22","Type":"Other","Title":"Modified"}]}}}