Spoofing attack in IBM WebSphere Application Server - CVE-2018-1902
Published: June 15, 2023
Vulnerability identifier: #VU77330
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1902
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can spoof connection information which could be used to launch further attacks against the system.
Affected software
IBM WebSphere Application Server
IBM Cloud Transformation Advisor
IBM Cloud Transformation Advisor
How to mitigate CVE-2018-1902
Install updates from vendor's website.
IBM Cloud Transformation Advisor - update to 1.9.5