
CVE-2015-5004
https://notcve.org/view.php?id=CVE-2015-5004
15 Dec 2015 — The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors. El Edge Component Caching Proxy en IBM WebSphere Application Server (WAS) 8.0 en versiones anteriores a 8.0.0.12 y 8.5 en versiones anteriores a 8.5.5.8 no cifra los datos adecuadamente, lo que permite a usuarios remotos autenticados obtener información sensible a ... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI41476 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-2017
https://notcve.org/view.php?id=CVE-2015-2017
08 Nov 2015 — CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. Vulnerabilidad de inyección CRLF en IBM WebSphere Application Server (WAS) 6.1 hasta la versión 6.1.0.47, 7.0 en versiones anteriores a 7.0.0.39, 8.0 en versiones anteriores a 8.0.0.12 y 8.5 en versiones anteriores a 8.5.5.8 permite a... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI45266 •

CVE-2015-1932
https://notcve.org/view.php?id=CVE-2015-1932
22 Aug 2015 — IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header. Vulnerabilidad en IBM WebSpher Application Server en 7.x en versiones anteriores a 7.0.0.39, 8.0.x en versiones anteriores a 8.0.0.11, 8.5.x en versiones anteriores a 8.5.5.7 y WebSphere Virtual Enterprise en versiones anteriores a... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI38403 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-4938
https://notcve.org/view.php?id=CVE-2015-4938
22 Aug 2015 — IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors. Vulnerabilidad en IBM WebSphere Application Server en 7.x en versiones anteriores a 7.0.0.39, 8.0.x en versiones anteriores a 8.0.0.11, 8.5.x en versiones anteriores a 8.5.5.7, permite a atacantes remotos suplantar servlets y obtener información sensible a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI37396 •

CVE-2015-1927
https://notcve.org/view.php?id=CVE-2015-1927
14 Jul 2015 — The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors. La configuración por defecto de WebSphere Application Server (WAS) de IBM 7.0.0 anteriores a 7.0.0.39, 8.0.0 anteriores a 8.0.0.11 y 8.5 anteriores a 8.5.5.6, posee un valor falso en la ... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI31622 • CWE-284: Improper Access Control •

CVE-2015-1936
https://notcve.org/view.php?id=CVE-2015-1936
14 Jul 2015 — The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter. La consola administrativa de WebSphere Application Server (WAS) de IBM 8.0.0 anteriores a 8.0.0.11 y 8.5 anteriores a 8.5.5.6, cuando la característica de seguridad está deshabilitada, permite a usuarios autenticados remotamente secuestrar las sesiones a través de los paráme... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI37230 • CWE-284: Improper Access Control •

CVE-2015-1946
https://notcve.org/view.php?id=CVE-2015-1946
14 Jul 2015 — IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors. WebSphere Application Server (WAS) 8.5 anteriores a 8.5.5.6 y WebSphere Virtual Enterprise 7.0 anteriores a 7.0.0.6 para WebSphere Application Server (WAS) 7.0 y 8.0, no tienen los roles de usuarios correctamente implementados lo que permit... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI35180 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-1920 – Samsung KNOX 1.0 VPN Man-In-The-Middle
https://notcve.org/view.php?id=CVE-2015-1920
20 May 2015 — IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session. IBM WebSphere Application Server (WAS) 6.1 hasta 6.1.0.47, 7.0 anterior a 7.0.0.39, 8.0 anterior a 8.0.0.11, y 8.5 anterior a 8.5.5.6 permite a atacantes remotos ejecutar código arbitrario mediante el envío de instrucciones manipuladas en una sesión management-port. Samsung... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI38302 • CWE-284: Improper Access Control •