CVE-2015-1936

Publication date

2015-07-14 17:00:00

Family

ibm

State

PUBLISHED

Description

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.