Security Bulletin
Summary
WebSphere Application Server is shipped as a component of SmartCloud Cost Management. WebSphere Application Server is shipped as a component of Tivoli Integrated Portal, which is shipped as a component of Tivoli Usage and Accounting Manager. Information about a security vulnerability affecting WebSphere Application Server has been published in security bulletins.
Vulnerability Details
CVEID: CVE-2015-1927
DESCRIPTION: IBM WebSphere Application Server could allow a remote attacker to gain elevated privileges on the system, caused by an application not having the correct serveServletsbyClassname setting. By a developer not setting the correct property, an attacker could exploit this vulnerability to gain unauthorized access.
CVSS Base Score: 6.8
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Affected Products and Versions
|
Principal Product and Version(s) | Affected Supporting Product and Version |
IBM Tivoli Usage and Accounting Manager V2.1, V2.1.0.1, V7.3.0.4 | IBM Tivoli Integrated Portal, Version 2.2 and all fixpacks |
IBM SmartCloud Cost Management V2.1.0.3, V2.1.0.4 | Websphere Application Server Liberty Profile V8.5.5 |
Remediation/Fixes
If you are running IBM SmartCloud Cost Management V2.1.0.3, V2.1.0.4, refer to the WAS security bulletin to remediate the vulnerabilities related to - Multiple Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.5.6.
If you are running IBM Tivoli Usage and Accounting Manager V2.1, V2.1.0.1, V7.3.0.4, refer to the security bulletin to remediate the vulnerabilities related to Tivoli Integrated Portal - IBM Tivoli Integrated Portal Recommends to Install IBM Websphere Application Server Fixes to fix Multiple Security Vulnerabilities.
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg21964651