Authentication Bypass by Spoofing in IBM WebSphere Application Server - CVE-2018-1695
Published: December 20, 2023
Vulnerability identifier: #VU84604
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1695
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can spoof page content.
Affected software
IBM WebSphere Application Server
Tivoli Network Manager IP Edition
IBM Tivoli Netcool Configuration Manager
Tivoli Network Manager IP Edition
IBM Tivoli Netcool Configuration Manager
How to mitigate CVE-2018-1695
Install updates from vendor's website.