Improper Authentication in WebSphere Portal - CVE-2018-1672
Published: October 1, 2018 / Updated: August 8, 2020
Vulnerability identifier: #VU36598
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1672
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to read and manipulate data.
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.
Affected software
WebSphere Portal
How to mitigate CVE-2018-1672
Install update from vendor's website.