#VU13184 Man-in-the-middle attack in IBM Corporation products - CVE-2018-1454
Published: June 5, 2018
Vulnerability identifier: #VU13184
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-1454
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
IBM InfoSphere Information Governance Catalog
IBM InfoSphere Data Click
IBM InfoSphere Information Server for Cloud
IBM InfoSphere Information Governance Catalog
IBM InfoSphere Data Click
IBM InfoSphere Information Server for Cloud
Software vendor:
IBM Corporation
IBM Corporation
Description
The vulnerability allows a remote attacker to conduct man-in-the-middle attack.
The vulnerability exists due to system does not properly enable HTTP Strict Transport Security. A remote attacker can conduct man-in-the-middle attack, intercept of the communication channel between the affected app and access arbitrary data.
Remediation
Install update from vendor's website.