CVE-2015-1946: IBM WebSphere Application Server

Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.

Affected products

  • IBM WebSphere Application Server: version 7.0 only; version 8.0.0.0 only; version 8.5.0.0 only; version 8.5.0.1 only; version 8.5.0.2 only; version 8.5.5.0 only; …
  • IBM WebSphere Virtual Enterprise: version 7.0 only; version 7.0.0.1 only; version 7.0.0.2 only; version 7.0.0.3 only; version 7.0.0.4 only; version 7.0.0.5 only

Published 2015-07-14. Last modified 2026-06-17.