The Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 allows remote attackers to hijack sessions via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/77476
https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-3282
http://www.ibm.com/support/docview.wss?uid=swg21611313