IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console. An authenticated remote attacker could exploit this vulnerability to possibly gain elevated privileges.
https://exchange.xforce.ibmcloud.com/vulnerabilities/134912
http://www.securitytracker.com/id/1040356