CVE-2018-1420

Severity
6.5MEDIUM
EPSS
0.1%
top 65.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMay 13

Description

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/websphere_portal4 versions+3
NVDibm/websphere_portal7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xxr9-6j7m-9mvq: IBM WebSphere Portal 72022-05-13
CVEList
CVE-2018-1420: IBM WebSphere Portal 72018-10-01

💥Exploits & PoCs

1
Exploit-DB
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)2018-04-03