Use of a broken or risky cryptographic algorithm in WebSphere Application Server Admin Console - CVE-2018-1996

 

Use of a broken or risky cryptographic algorithm in WebSphere Application Server Admin Console - CVE-2018-1996

Published: October 13, 2023


Vulnerability identifier: #VU81993
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1996
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.


Affected software

WebSphere Application Server Admin Console
IBM Tivoli Netcool Configuration Manager
IBM Tivoli Network Manager (ITNM)

How to mitigate CVE-2018-1996

Install updates from vendor's website.


External References

Related Security Bulletins