CVE-2018-1886
Last modified
CVE-2018-1886 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021.
Metrics
CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Access Manager | >= 9.0.1.0, <= 9.0.5.0 |
References
- http://www.ibm.com/support/docview.wss?uid=ibm10787785Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/152021VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10787785Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/152021VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1886?
How severe is CVE-2018-1886?
How do I fix CVE-2018-1886?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18853Lightbend Spray spray-json through 1.3.4 allows remote attac…
- CVE-2018-18854Lightbend Spray spray-json through 1.3.4 allows remote attac…
- CVE-2018-18856Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-18857Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-18858Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-18859Multiple local privilege escalation vulnerabilities have bee…
- CVE-2018-18860A local privilege escalation vulnerability has been identifi…
- CVE-2018-18861Buffer overflow in PCMan FTP Server 2.0.7 allows for remote …
- CVE-2018-18862BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR …
- CVE-2018-18863NGA ResourceLink 20.0.2.1 allows local file inclusion.
- CVE-2018-18864Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS beca…
- CVE-2018-18865The Royal browser extensions TS before 4.3.60728 (Release Da…
Are you affected by CVE-2018-1886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
