CVE-2015-1882Race Condition in IBM Websphere Application Server

CWE-362Race Condition3 documents3 sources
Severity
8.5HIGHNVD
EPSS
2.2%
top 15.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 17

Description

Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configured EJB Run-as user.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 6.8 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wf3j-ph5h-5r7q: Multiple race conditions in IBM WebSphere Application Server (WAS) 82022-05-17
CVEList
CVE-2015-1882: Multiple race conditions in IBM WebSphere Application Server (WAS) 82015-04-26
CVE-2015-1882 — Race Condition in IBM | cvebase