CVE-2018-1595

HIGH

IBM Spectrum Symphony/Platform Symphony <7.2.0.2 - Command Injection

Title source: llm
STIX 2.1

Description

IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104956
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=isg3T1027819
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/143622

Scores

CVSS v3 8.8
EPSS 0.0242
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (5)
ibm/platform_symphony 6.1.1
ibm/platform_symphony 7.1.0
ibm/platform_symphony 7.1.1
ibm/spectrum_symphony 7.1.2
ibm/spectrum_symphony 7.2.0.2
Published Aug 01, 2018
Tracked Since Feb 18, 2026