Spoofing attack in IBM WebSphere Application Server - CVE-2018-1902

 

Spoofing attack in IBM WebSphere Application Server - CVE-2018-1902

Published: June 15, 2023


Vulnerability identifier: #VU77330
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1902
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can spoof connection information which could be used to launch further attacks against the system.


Affected software

IBM WebSphere Application Server
IBM Cloud Transformation Advisor

How to mitigate CVE-2018-1902

Install updates from vendor's website.

IBM Cloud Transformation Advisor - update to 1.9.5

External References

Related Security Bulletins