Improper access control in IBM WebSphere Application Server - CVE-2018-1901
Published: June 15, 2023
Vulnerability identifier: #VU77331
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1901
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to incorrect cached value being used. A remote user can bypass implemented security restrictions and escalate privileges on the system.
Affected software
IBM WebSphere Application Server
IBM Cloud Transformation Advisor
IBM Cloud Transformation Advisor
How to mitigate CVE-2018-1901
Install updates from vendor's website.
IBM Cloud Transformation Advisor - update to 1.9.2