{"api_version":"1","generated_at":"2026-07-23T06:11:47+00:00","cve":"CVE-2015-4947","urls":{"html":"https://cve.report/CVE-2015-4947","api":"https://cve.report/api/cve/CVE-2015-4947.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4947","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4947"},"summary":{"title":"CVE-2015-4947","description":"Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.","state":"PUBLISHED","assigner":"ibm","published_at":"2015-09-15 15:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI44793","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI44793","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.securityfocus.com/bid/76658","name":"http://www.securityfocus.com/bid/76658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM HTTP Server CVE-2015-4947 Stack Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1033512","name":"http://www.securitytracker.com/id/1033512","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM HTTP Server (IHS) Stack Overflow Lets Remote Authenticated Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21965419","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21965419","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Security Bulletin: Stack Buffer overflow may affect IBM HTTP Server (CVE-2015-4947) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI45596","name":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI45596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4947","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4947","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4947","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"http_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4947","vulnerable":"1","versionEndIncluding":"6.1.0.47","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"http_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:32:31.917Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21965419"},{"name":"76658","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76658"},{"name":"PI45596","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI45596"},{"name":"PI44793","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI44793"},{"name":"1033512","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033512"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-09-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-20T16:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21965419"},{"name":"76658","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76658"},{"name":"PI45596","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI45596"},{"name":"PI44793","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI44793"},{"name":"1033512","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033512"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2015-4947","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21965419","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21965419"},{"name":"76658","refsource":"BID","url":"http://www.securityfocus.com/bid/76658"},{"name":"PI45596","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI45596"},{"name":"PI44793","refsource":"AIXAPAR","url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PI44793"},{"name":"1033512","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033512"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2015-4947","datePublished":"2015-09-15T15:00:00.000Z","dateReserved":"2015-06-24T00:00:00.000Z","dateUpdated":"2024-08-06T06:32:31.917Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-09-15 15:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.0.0","versionEndIncluding":"6.1.0.47","matchCriteriaId":"78F18FE4-83BA-432A-9C0C-0FAC4314E050"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0.0","versionEndExcluding":"7.0.0.39","matchCriteriaId":"07BDE0FE-10BB-4F11-8A59-720987298913"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0.0","versionEndExcluding":"8.0.0.12","matchCriteriaId":"C8AD985A-F098-47F6-90B5-D5A3285736D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:http_server:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0.0","versionEndExcluding":"8.5.5.7","matchCriteriaId":"1FB17D1E-FEF4-4E1B-88A7-764CA673A686"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4947","Ordinal":"1","Title":"CVE-2015-4947","CVE":"CVE-2015-4947","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4947","Ordinal":"1","NoteData":"Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.","Type":"Description","Title":"CVE-2015-4947"},{"CveYear":"2015","CveId":"4947","Ordinal":"2","NoteData":"2015-09-15","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4947","Ordinal":"3","NoteData":"2016-12-20","Type":"Other","Title":"Modified"}]}}}