Improper Authentication in WebSphere Portal - CVE-2018-1672

 

Improper Authentication in WebSphere Portal - CVE-2018-1672

Published: October 1, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36598
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1672
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to read and manipulate data.

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.


Affected software

WebSphere Portal

How to mitigate CVE-2018-1672

Install update from vendor's website.


External References

Related Security Bulletins