CVE-2018-1453

HIGH

IBM Security Identity Manager Virtual Appliance 7.0 - File Upload

Title source: llm
STIX 2.1

Description

IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. IBM X-Force ID: 140055.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg22013617
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041383
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/140055

Scores

CVSS v3 8.8
EPSS 0.0032
EPSS Percentile 54.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
ibm/security_identity_manager 7.0
ibm/security_identity_manager 7.0.1
Published Jun 08, 2018
Tracked Since Feb 18, 2026