CVE-2015-1885
EUVD-2015-199027.04.2015, 12:59
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attackers to gain privileges via unspecified vectors.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | websphere_application_server | 7.0 |
| ibm | websphere_application_server | 7.0.0.1 |
| ibm | websphere_application_server | 7.0.0.2 |
| ibm | websphere_application_server | 7.0.0.3 |
| ibm | websphere_application_server | 7.0.0.10 |
| ibm | websphere_application_server | 7.0.0.11 |
| ibm | websphere_application_server | 7.0.0.12 |
| ibm | websphere_application_server | 7.0.0.13 |
| ibm | websphere_application_server | 7.0.0.14 |
| ibm | websphere_application_server | 7.0.0.15 |
| ibm | websphere_application_server | 7.0.0.16 |
| ibm | websphere_application_server | 7.0.0.17 |
| ibm | websphere_application_server | 7.0.0.18 |
| ibm | websphere_application_server | 7.0.0.19 |
| ibm | websphere_application_server | 7.0.0.21 |
| ibm | websphere_application_server | 7.0.0.22 |
| ibm | websphere_application_server | 7.0.0.23 |
| ibm | websphere_application_server | 7.0.0.24 |
| ibm | websphere_application_server | 7.0.0.25 |
| ibm | websphere_application_server | 7.0.0.27 |
| ibm | websphere_application_server | 7.0.0.29 |
| ibm | websphere_application_server | 7.0.0.31 |
| ibm | websphere_application_server | 7.0.0.32 |
| ibm | websphere_application_server | 7.0.0.33 |
| ibm | websphere_application_server | 7.0.0.34 |
| ibm | websphere_application_server | 7.0.0.35 |
| ibm | websphere_application_server | 7.0.0.36 |
| ibm | websphere_application_server | 7.0.0.37 |
| ibm | websphere_application_server | 7.0.0.38 |
| ibm | websphere_application_server | 8.5.0.0 |
| ibm | websphere_application_server | 8.5.0.1 |
| ibm | websphere_application_server | 8.5.0.2 |
| ibm | websphere_application_server | 8.5.5.0 |
| ibm | websphere_application_server | 8.5.5.1 |
| ibm | websphere_application_server | 8.5.5.2 |
| ibm | websphere_application_server | 8.5.5.3 |
| ibm | websphere_application_server | 8.5.5.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References