CVE-2018-1420
Last modified
CVE-2018-1420 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
Metrics
CVSS:3.0/A:N/AC:H/AV:N/C:N/I:H/PR:L/S:U/UI:N/E:U/RC:C/RL:O
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Portal | 7.0.0.0 |
| Ibm | Websphere Portal | 7.0.0.1 |
| Ibm | Websphere Portal | 7.0.0.2 |
| Ibm | Websphere Portal | 8.0.0.0 |
| Ibm | Websphere Portal | 8.0.0.1 |
| Ibm | Websphere Portal | 8.5.0.0 |
| Ibm | Websphere Portal | 9.0.0.0 |
References
- http://www.securitytracker.com/id/1041767Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/138950VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=swg22014276Patch, Vendor Advisory
- http://www.securitytracker.com/id/1041767Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/138950VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=swg22014276Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1420?
How severe is CVE-2018-1420?
How do I fix CVE-2018-1420?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1414IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL…
- CVE-2018-1415IBM Maximo Asset Management 7.6 is vulnerable to cross-site …
- CVE-2018-1416IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to…
- CVE-2018-1417Under certain circumstances, a flaw in the J9 JVM (IBM SDK, …8.1
- CVE-2018-1418IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to b…
- CVE-2018-1419IBM WebSphere MQ 8.0 and 9.0, when configured to use a PAM m…3.7
- CVE-2018-1421IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5…7.1
- CVE-2018-1422IBM Jazz Foundation products (IBM Rational DOORS Next Genera…5.4
- CVE-2018-1423IBM Jazz Foundation products could disclose sensitive inform…4.3
- CVE-2018-1424IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable …7.1
- CVE-2018-14241This vulnerability allows remote attackers to execute arbitr…
- CVE-2018-14242This vulnerability allows remote attackers to execute arbitr…
Are you affected by CVE-2018-1420?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
