CVE-2018-1840
MEDIUMIBM Websphere Application Server < 8.5.5.14 - Exposure to Wrong Actor
Title source: ruleDescription
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then migrated to a newer release of WebSphere Application Server. IBM X-Force ID: 150813.
Scores
CVSS v3
6.0
EPSS
0.0067
EPSS Percentile
71.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Classification
CWE
CWE-668
Status
published
Affected Products (1)
ibm/websphere_application_server
< 8.5.5.14
Timeline
Published
Dec 03, 2018
Tracked Since
Feb 18, 2026