Security Advisory
CVE-2015-1936
6
Vulnerability Description
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
Published Date
July 14, 2015
Official Source
NIST NVD Advisory