CVE-2018-1899

MEDIUM

IBM InfoSphere Information Server <11.8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10744029
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/152528

Scores

CVSS v3 4.3
EPSS 0.0054
EPSS Percentile 42.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (5)
ibm/infosphere_information_governance_catalog 11.3
ibm/infosphere_information_governance_catalog 11.5
ibm/infosphere_information_governance_catalog 11.7
ibm/infosphere_information_server_on_cloud 11.5
ibm/infosphere_information_server_on_cloud 11.7
Published Mar 05, 2019
Tracked Since Feb 18, 2026