CVE-2015-1936 - Madagascar Ditches
Description
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6 when the Security feature is disabled allows remote authenticated users to hijack sessions via the JSESSIONID parameter.
Reference
http://www-01.ibm.com/support/docview.wss?uid=swg21959083 http://www-01.ibm.com/support/docview.wss?uid=swg1PI37230 http://www.securityfocus.com/bid/75480