VulnerabilityModified
CVE-2018-1623
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system.
LOW 3.3EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 144408.
- CVSS 3.0
- 3.3 LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/security privileged identity manager
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10879093Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/144408VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10879093Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/144408VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.