CVE-2015-1920: IBM WebSphere Application Server
High severity, CVSS 10.0. EPSS: 6.8% chance of exploitation in the next 30 days.
IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by sending crafted instructions in a management-port session.
Affected products
- IBM WebSphere Application Server: version 6.1 only; version 6.1.0 only; version 6.1.0.0 only; version 6.1.0.1 only; version 6.1.0.2 only; version 6.1.0.3 only; …
Published 2015-05-20. Last modified 2026-06-17.