VulnerabilityModified
CVE-2018-1420
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation.
MEDIUM 6.5EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- ibm/websphere portal
- Source
- psirt@us.ibm.com
References
- http://www.securitytracker.com/id/1041767Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/138950VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=swg22014276Patch, Vendor Advisory
- http://www.securitytracker.com/id/1041767Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/138950VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=swg22014276Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.