CVE-2015-1936: IBM WebSphere Application Server
Medium severity, CVSS 6.0. EPSS: 1.7% chance of exploitation in the next 30 days.
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
Affected products
- IBM WebSphere Application Server: version 8.0.0.0 only; version 8.0.0.1 only; version 8.0.0.2 only; version 8.0.0.3 only; version 8.0.0.4 only; version 8.0.0.5 only; …
Published 2015-07-14. Last modified 2026-06-17.